Bug#1144059: roundcube: Multiple security vulnerabilities

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Hi Guilhem,

On Mon, Aug 10, 2026 at 02:30:56PM +0200, Guilhem Moulin wrote:
> Source: roundcube
> Version: 1.6.17+dfsg-1
> Control: found -1 1.6.17+dfsg-0+deb13u1
> Control: found -1 1.6.5+dfsg-1+deb12u10
> Control: found -1 1.4.15+dfsg.1-1+deb11u10
> Severity: grave
> Tags: security upstream
> Justification: user security hole
> X-Debbugs-Cc: Debian Security Team <[email protected]>
> 
> Roundcube webmail upstream has recently released 1.6.17 [0] which fixes
> the following security vulnerabilities:
> 
>  1. Content proxied by the css proxy is not validated validation
>     https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
>  2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
>     fe80::/10 subnets
>     https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
>  3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
>     evading is_local_url() check
>     https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
>  4. Remote content blocking bypass via unclosed url() in a FuncIRI
>     attribute
>     https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
>  5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
>     `search_filter`
>     https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
>  6. Arbitrary sieve script injection via a filter rule name bypassing
>     `managesieve_disabled_actions`
>     https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
>  7. RCE in the `cmd_learn` driver of markasjunk plugin
>     https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
>     Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
>  8. IMAP command injection via mail search and LITERAL+ byte-count
>     desynchronization
>     https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
>  9. The modoboa driver of the passwd plugin leaks an authentication
>     token to a user-controlled host
>     https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
>  10. Stored XSS in “Add to address book” action
>      https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
>  11. HTML/CSS sanitization bypass via SVG animate `by` attribute
>      https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
> 
> (Using severity=grave due to issues #7 and #9, although they are
> specific to plugins which are not enabled by default.)
> 
> AFAIK no CVE-ID have been published for these issues.  I'll request some
> later today unless someone beats me to it.

If you can request them that would be great, thank you.

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.