stable

roundcubemail-0.9.5-1.el6

FEDORA-EPEL-2013-11925 created by limb 11 years ago for Fedora EPEL 6

Roundcubemail just released new 0.9.5 version with fixes for VCE2013-6172(will be available soon).

Hotfix: https://github.com/roundcube/roundcubemail/commit/4109bb26ce.diff

Full announcement:

We just published new releases which fix a recently reported vulnerability that allows an attacker to overwrite configuration settings using user preferences. This can result in random file access, manipulated SQL queries and even code execution. The latter one only affects versions 0.8.6 and older.

Beside the security fix, the 0.9.5 release also includes other minor bug fixes and improvements. Most notably it brings the default spell checker back after Google suspended their public spell checking service.

This update has been submitted for testing by limb.

11 years ago

This update is currently being pushed to the Fedora EPEL 6 testing updates repository.

11 years ago

This update has been pushed to testing

11 years ago

Thanks!

karma: +1

User Icon mikaku provided feedback 11 years ago
karma
User Icon cicku commented & provided feedback 11 years ago
karma

works.

User Icon lbazan provided feedback 11 years ago
karma

This update has reached the stable karma threshold and will be pushed to the stable updates repository

11 years ago

This update is currently being pushed to the Fedora EPEL 6 stable updates repository.

11 years ago

This update has been pushed to stable

11 years ago

Please log in to add feedback.

Metadata
Type
security
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
11 years ago
in testing
11 years ago
in stable
11 years ago
BZ#1021735 CVE-2013-6172: Vulnerability in handling _session argument of utils/save-prefs [fedora-all]
0
0
BZ#1021965 CVE-2013-6172 roundcubemail: vulnerability in handling _session argument of utils/save-prefs [epel-all]
0
0

Automated Test Results