USN-7200-1: Roundcube vulnerability
Published Jan 13, 2025
·Updated
It was discovered that Roundcube incorrectly handled certain file-based attachment plugins. An attacker could exploit this to gain unauthorized access to arbitrary files on the host’s file system.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/roundcube-core<1.2~beta+dfsg.1-0ubuntu1+esm5
1.2~beta+dfsg.1-0ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/roundcube-plugins<1.2~beta+dfsg.1-0ubuntu1+esm5
1.2~beta+dfsg.1-0ubuntu1+esm5
Ubuntu Ubuntu=16.04
Event History
Jan 13, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7200-1?
The severity of USN-7200-1 is classified as high due to the potential for unauthorized access to arbitrary files.
2
How do I fix USN-7200-1?
To fix USN-7200-1, update the Roundcube installation to version 1.2~beta+dfsg.1-0ubuntu1+esm5.
3
What components are affected by USN-7200-1?
USN-7200-1 affects the roundcube-core and roundcube-plugins packages on Ubuntu 16.04.
4
What vulnerabilities are associated with USN-7200-1?
USN-7200-1 addresses vulnerabilities related to improper handling of file-based attachment plugins in Roundcube.
5
Can I continue to use Roundcube without addressing USN-7200-1?
Continuing to use Roundcube without addressing USN-7200-1 poses a significant security risk and is not recommended.