First published: Mon Jan 13 2025(Updated: )
It was discovered that Roundcube incorrectly handled certain file-based attachment plugins. An attacker could exploit this to gain unauthorized access to arbitrary files on the host’s file system.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/roundcube-core | <1.2~beta+dfsg.1-0ubuntu1+esm5 | 1.2~beta+dfsg.1-0ubuntu1+esm5 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/roundcube-plugins | <1.2~beta+dfsg.1-0ubuntu1+esm5 | 1.2~beta+dfsg.1-0ubuntu1+esm5 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.