CVE-2018-9846: Input Validation
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "uid" parameter (in an archive.php task=mail&mbox=INBOX&action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/roundcubeto a version that resolves this vulnerability.Fixed in 1.3.17+dfsg.1-1~deb10u2Fixed in 1.3.17+dfsg.1-1~deb10u3Fixed in 1.4.14+dfsg.1-1~deb11u1Fixed in 1.4.13+dfsg.1-1~deb11u1Fixed in 1.6.3+dfsg-1~deb12u1Fixed in 1.6.4+dfsg-1 - Upgrade
Upgrade
roundcubeto a version that resolves this vulnerability.Fixed in 1.3.4 - Upgrade
Upgrade
roundcubeto a version that resolves this vulnerability.Fixed in 1.3.5
Event History
Frequently Asked Questions
What is CVE-2018-9846?
CVE-2018-9846 is a vulnerability in Roundcube versions 1.2.0 to 1.3.5 with the archive plugin enabled and configured.
What is the severity of CVE-2018-9846?
CVE-2018-9846 has a severity score of 8.8 (high).
How can CVE-2018-9846 be exploited?
CVE-2018-9846 can be exploited through an MX (IMAP) injection attack using the unsanitized '_uid' parameter in the 'archive.php' file.
Which software is affected by CVE-2018-9846?
Roundcube versions 1.2.0 to 1.3.5 with the archive plugin enabled and configured are affected. Additionally, Roundcube Webmail and Debian Linux version 9.0 are also affected.
How can I fix the CVE-2018-9846 vulnerability?
To fix the CVE-2018-9846 vulnerability, update Roundcube to version 1.3.17+dfsg.1-1~deb10u2, 1.3.17+dfsg.1-1~deb10u3, 1.4.14+dfsg.1-1~deb11u1, 1.4.13+dfsg.1-1~deb11u1, 1.6.3+dfsg-1~deb12u1, or 1.6.4+dfsg-1.