CVE-2024-37385: Command Injection
Published Jun 7, 2024
·Updated
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via imconvertpath and imidentifypath. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
Affected Software
4 affected components
Roundcube Webmail<1.5.7, >1.6.0<1.6.7
All of the following
Any of the following
Roundcube Webmail<1.5.7
Roundcube Webmail>=1.6.0<1.6.7
Microsoft Windows
Remediation
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 7, 2024
CVE Published
via NVD·04:15 AM
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 20, 2024
Data Sourced
via MITRE·04:03 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-37385?
CVE-2024-37385 has a severity rating according to its potential impact on system security, primarily concerning command injection vulnerabilities.
2
How do I fix CVE-2024-37385?
To fix CVE-2024-37385, upgrade to Roundcube Webmail version 1.5.7 or 1.6.7 or later.
3
What systems are affected by CVE-2024-37385?
CVE-2024-37385 affects Roundcube Webmail versions prior to 1.5.7 and 1.6.x versions before 1.6.7 on Windows.
4
What type of vulnerability is CVE-2024-37385?
CVE-2024-37385 is classified as a command injection vulnerability.
5
Is CVE-2024-37385 related to any other vulnerabilities?
Yes, CVE-2024-37385 is related to an incomplete fix for CVE-2020-12641.