Source: roundcube
Version: 1.6.15+dfsg-1
Control: found -1 1.6.15+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u8
Control: found -1 1.4.15+dfsg.1-1+deb11u8
Severity: grave
Justification: user security hole
Tags: security upstream
X-Debbugs-Cc: Debian Security Team <[email protected]>

Roundcube webmail upstream has recently released 1.6.16 [0] which fixes
the following security vulnerabilities:

  1. Stored XSS/HTML/CSS injection in subject field of the draft restore
     dialog.
  2. CSS injection bypass in HTML sanitizer via SVG <animate
     attributeName="style">.
  3. Pre-auth SQL injection in virtuser_query plugin via preg_replace
     backslash escape bypass.
  4. SSRF bypass via specific local address URLs.
  5. Local/private URL fetch bypass when remote resources were not
     allowed.
  6. Bypass of remote image blocking via CSS var().
  7. Pre-auth arbitrary file delete via redis/memcache session poisoning
     bypass.
  8. Code injection vulnerability via code evaluation support in LDAP
     autovalues option.  Code evaluation support has now been removed.

AFAIK no CVE-ID have been published for these issues.  I'll requested
some later today unless someone beats me to it.
-- 
Guilhem.

[0] https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1

Attachment: signature.asc
Description: PGP signature

Reply via email to