CVE-2015-5382: Infoleak
Published May 23, 2017
·Updated
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the alt parameter when uploading a vCard.
Affected Software
5 affected components
Roundcube Roundcube Webmail<=1.0.5
Roundcube Roundcube Webmail=1.1.1
Roundcube Webmail=1.1
Roundcube Webmail=1.1-beta
Roundcube Webmail=1.1-rc
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5382?
CVE-2015-5382 has a medium severity rating as it allows remote authenticated users to read arbitrary files.
2
How do I fix CVE-2015-5382?
To fix CVE-2015-5382, upgrade to Roundcube Webmail version 1.0.6 or 1.1.2 or higher.
3
Which versions of Roundcube are affected by CVE-2015-5382?
CVE-2015-5382 affects Roundcube Webmail versions prior to 1.0.6 and 1.1.x before 1.1.2.
4
Can unauthenticated users exploit CVE-2015-5382?
No, CVE-2015-5382 can only be exploited by remote authenticated users.
5
What is the exploit method for CVE-2015-5382?
The exploit method for CVE-2015-5382 involves using the _alt parameter while uploading a vCard.