Debian Security Advisory

DLA-737-1 roundcube -- LTS security update

Date Reported:
08 Dec 2016
Affected Packages:
roundcube
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 847287.
More information:

It was discovered that there was a vulnerability where a remote user could execute arbitrary commands in Roundcube, a webmail solution for IMAP servers, by sending a specially crafted email.

This was due to lack of sanitisation of the arguments to PHP's mail function.

For Debian 7 Wheezy, this issue has been fixed in roundcube version 0.7.2-9+deb7u5.

We recommend that you upgrade your roundcube packages.