Debian Security Advisory
DLA-737-1 roundcube -- LTS security update
- Date Reported:
- 08 Dec 2016
- Affected Packages:
- roundcube
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 847287.
- More information:
-
It was discovered that there was a vulnerability where a remote user could execute arbitrary commands in Roundcube, a webmail solution for IMAP servers, by sending a specially crafted email.
This was due to lack of sanitisation of the arguments to PHP's
mail
function.For Debian 7
Wheezy
, this issue has been fixed in roundcube version 0.7.2-9+deb7u5.We recommend that you upgrade your roundcube packages.