New User, Welcome!     Login

Roundcube Webmail

[ MDVSA-2012:072 ] roundcubemail

 Mandriva Linux Security Advisory                         MDVSA-2012:072
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : roundcubemail
 Date    : May 10, 2012
 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

POC for CVE-2008-5619 (roundcubemail PHP arbitrary code injection)

Vulnerability reported by: RealMurphy


Intro
----
Roundcube Webmail is a browser-based IMAP client that uses
"chuggnutt.com HTML to Plain Text Conversion" library to convert
HTML text to plain text, this library uses the preg_replace PHP
function in an insecure manner.

Vulnerable versions:

[ MDVSA-2010:015 ] roundcubemail

 Mandriva Linux Security Advisory                         MDVSA-2010:015
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : roundcubemail
 Date    : January 19, 2010
 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

Unsanitized scripting in RoundCube webmail

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Site address: http://roundcube.net/

Roundcube webmail does not sanitize Microsoft Internet Explorer
scripting issues reported by Yosuke Hasegawa. Author was contacted on
2007-05-11. I haven't received any response and current (2007-12-09)
code is still vulnerable.


[ MDVSA-2010:048 ] roundcubemail

 Mandriva Linux Security Advisory                         MDVSA-2010:048
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : roundcubemail
 Date    : February 25, 2010
 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!