stable

roundcubemail-1.7.1-1.fc44

FEDORA-2026-2b956d89d3 created by remi 3 months ago for Fedora 44

Release 1.7.1

  • Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314)
  • Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186)
  • Clarified Elastic installation instructions (#10163)
  • Added HTMLFormElement.requestSubmit() polyfill for older browsers (#10179)
  • Fix so "has:attachment" search uses $HasAttachment/$HasNoAttachment keywords (#10168)
  • Fix potential too long value in IMAP ID command (#10136)
  • Fix redis/memcache disconnection in rcube::sleep() (#10127)
  • Fix so static resources, e.g. skin_logo can be put inside the public_html directory (#10160)
  • Fix so REQUEST_URI is used as a fallback if PATH_INFO is not set in static.php (#10181)
  • Fix assets_path feature and remove dependency on PATH_INFO (#10185)
  • Fix MySQL upgrade on MySQL < 8.0 and MariaDB < 10.5.3 (#10188)
  • Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog
  • Security: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style">
  • Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass
  • Security: Fix SSRF bypass via specific local address URLs
  • Security: Fix bypass of remote image blocking via CSS var()
  • Security: Fix local/private URL fetch bypass when remote resources were not allowed
  • Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass
  • Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-2b956d89d3

This update has been submitted for testing by remi.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago
User Icon pbrobinson commented & provided feedback 3 months ago
karma

Seems fine

User Icon amessina provided feedback 3 months ago
karma

This update can be pushed to stable now if the maintainer wishes

3 months ago

remi edited this update.

3 months ago

This update has been submitted for stable by bodhi.

2 months ago

This update has been pushed to stable.

2 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
2 months ago
modified
3 months ago
approved
3 months ago
BZ#2481615 CVE-2026-48842 roundcubemail: pre-auth SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass [fedora-all]
0
0
BZ#2481617 CVE-2026-48844 roundcubemail: code injection via insecure LDAP autovalues option [fedora-all]
0
0
BZ#2481619 CVE-2026-48843 roundcubemail: information disclosure and Server-Side Request Forgery via insufficient CSS sanitization [fedora-all]
0
0
BZ#2481622 CVE-2026-48845 roundcubemail: privilege escalation via remote image blocking bypass [fedora-all]
0
0
BZ#2481624 CVE-2026-48848 roundcubemail: CSS injection via an SVG document that has an animate element with the attributeName attribute [fedora-all]
0
0
BZ#2481626 CVE-2026-48847 roundcubemail: arbitrary file deletion via redis/memcache session poisoning bypass [fedora-all]
0
0
BZ#2481628 CVE-2026-48846 roundcubemail: remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message [fedora-all]
0
0
BZ#2481629 CVE-2026-48849 roundcubemail: XSS via unsanitized subject field in the draft restored value [fedora-all]
0
0

Automated Test Results