Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1016694
| From | Guilhem Moulin <guilhem@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#964355: roundcube: Cross-Site Scripting (XSS) vulnerability via HTML messages with malicious svg/namespace |
| Date | 2020-07-05 23:50 +0200 |
| Message-ID | <ApkGm-3RG-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Source: roundcube
Severity: important
Tags: security
Control: found -1 1.4.6+dfsg.1-3
Control: found -1 1.3.13+dfsg.1-1~deb10u1
Control: found -1 1.2.3+dfsg.1-4+deb9u5
AFAICT no CVE was assigned for this yet. 1.2.x, 1.3.x and 1.4.x
branches are affected. Upstream fix:
1.4.x https://github.com/roundcube/roundcubemail/commit/3e8832d029b035e3fcfb4c75839567a9580b4f82
1.3.x https://github.com/roundcube/roundcubemail/commit/19502419757a976dbd55ce5a746610c5bab7896b
1.2.x https://github.com/roundcube/roundcubemail/commit/f3d1566cf223eb04f47b6dfffcd88753f66c36ee
--
Guilhem.
Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread
Bug#964355: roundcube: Cross-Site Scripting (XSS) vulnerability via HTML messages with malicious svg/namespace Guilhem Moulin <guilhem@debian.org> - 2020-07-05 23:50 +0200
csiph-web