USN-6848-1: Roundcube vulnerabilities
Matthieu Faou and Denys Klymenko discovered that Roundcube incorrectly handled certain SVG images. A remote attacker could possibly use this issue to load arbitrary JavaScript code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 23.10. (CVE-2023-5631) Rene Rehme discovered that Roundcube incorrectly handled certain headers. A remote attacker could possibly use this issue to load arbitrary JavaScript code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 23.10. (CVE-2023-47272) Valentin T. and Lutz Wolf discovered that Roundcube incorrectly handled certain SVG images. A remote attacker could possibly use this issue to load arbitrary JavaScript code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 23.10. (CVE-2024-37383) Huy Nguyễn Phạm Nhật discovered that Roundcube incorrectly handled certain fields in user preferences. A remote attacker could possibly use this issue to load arbitrary JavaScript code. (CVE-2024-37384)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6848-1?
The severity of USN-6848-1 is considered high due to the potential for remote code execution via improperly handled SVG images.
How do I fix USN-6848-1?
To fix USN-6848-1, update Roundcube to version 1.6.2+dfsg-1ubuntu0.2 or later on affected Ubuntu versions.
Which Ubuntu versions are affected by USN-6848-1?
The affected Ubuntu versions for USN-6848-1 are 18.04 LTS, 20.04 LTS, 22.04 LTS, and 23.10.
What impact does USN-6848-1 have on my system?
USN-6848-1 allows an attacker to load arbitrary JavaScript code, posing a significant security risk to users.
Who discovered the vulnerability associated with USN-6848-1?
The vulnerability associated with USN-6848-1 was discovered by Matthieu Faou and Denys Klymenko.