CVE-2015-5383: Infoleak
Published May 23, 2017
·Updated
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
Affected Software
4 affected components
Roundcube Roundcube Webmail=1.1.1
Roundcube Webmail=1.1
Roundcube Webmail=1.1-beta
Roundcube Webmail=1.1-rc
Remediation
Patch Available
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5383?
CVE-2015-5383 is considered a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2015-5383?
To fix CVE-2015-5383, upgrade Roundcube Webmail to version 1.1.2 or later.
3
What are the affected versions for CVE-2015-5383?
Affected versions for CVE-2015-5383 include Roundcube Webmail 1.1.1 and earlier.
4
What kind of information can be accessed through CVE-2015-5383?
CVE-2015-5383 allows remote attackers to read files in the config, temp, or logs directory, potentially exposing sensitive information.
5
Is there a workaround for CVE-2015-5383 if immediate upgrade is not possible?
As a temporary workaround for CVE-2015-5383, consider restricting access to the config, temp, and logs directories until the update is applied.