stable

roundcubemail-1.6.11-1.fc41

FEDORA-2025-a5f56fe8ff created by remi a month ago for Fedora 41

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities:

  • Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Managesieve: Fix match-type selector (remove unsupported options) in delete header action (#9610)
  • Improve installer to fix confusion about disabling SMTP authentication (#9801)
  • Fix PHP warning in index.php (#9813)
  • OAuth: Fix/improve token refresh
  • Fix dark mode bug where wrong colors were used for blockquotes in HTML mail preview (#9820)
  • Fix HTML message preview if it contains floating tables (#9804)
  • Fix removing/expiring redis/memcache records when using a key prefix
  • Fix bug where a wrong SPECIAL-USE folder could have been detected, if there were more than one per-type (#9781)
  • Fix a default value and documentation of password_ldap_encodage option (#9658)
  • Remove mobile/floating Create button from the list in Settings > Folders (#9661)
  • Fix Delete and Empty buttons state while creating a folder (#9047)
  • Fix connecting to LDAP using ldapi:// URI (#8990)
  • Fix cursor position on "below the quote" reply in HTML mode (#8700)
  • Fix bug where attachments with content type of application/vnd.ms-tnef were not parsed (#7119)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-a5f56fe8ff

This update has been submitted for testing by remi.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

remi edited this update.

a month ago

This update has been pushed to testing.

a month ago
User Icon pbrobinson commented & provided feedback a month ago
karma

Tested on a x86 VM server, seems to work fine

BZ#2369708 CVE-2025-49113 roundcubemail: From CVEorg collector [fedora-41]

This update can be pushed to stable now if the maintainer wishes

a month ago

This update has been submitted for stable by bodhi.

a month ago
User Icon jbates provided feedback 4 weeks ago
karma
BZ#2369708 CVE-2025-49113 roundcubemail: From CVEorg collector [fedora-41]

This update has been pushed to stable.

4 weeks ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
4 weeks ago
modified
a month ago
approved
a month ago
BZ#2369708 CVE-2025-49113 roundcubemail: From CVEorg collector [fedora-41]
0
2

Automated Test Results