Site Navigation:
security roundcubemail-0.9.5-1.el6 security update
Status:stable
Release: Fedora EPEL 6
Update ID: FEDORA-EPEL-2013-11925
Builds: roundcubemail-0.9.5-1.el6 (logs)
Pushed: True
Date Submitted: 2013-10-22 12:57:34
Date Released: 2013-10-22 18:00:28
Submitter: limb
Karma: 3
Stable karma: 3
Unstable karma: -3
Details

Roundcubemail just released new 0.9.5 version with fixes for VCE2013-6172(will be available soon).

Hotfix: https://github.com/roundcube/roundcubemail/commit/4109bb26ce.diff

Full announcement:

We just published new releases which fix a recently reported vulnerability that allows an attacker to overwrite configuration settings using user preferences. This can result in random file access, manipulated SQL queries and even code execution. The latter one only affects versions 0.8.6 and older.

Beside the security fix, the 0.9.5 release also includes other minor bug fixes and improvements. Most notably it brings the default spell checker back after Google suspended their public spell checking service.

Bugs Fixed
1021735 - CVE-2013-6172: Vulnerability in handling _session argument of utils/save-prefs [fedora-all]
1021965 - CVE-2013-6172: roundcubemail: vulnerability in handling _session argument of utils/save-prefs [epel-all]
Feedback
bodhi - 2013-10-22 12:58:17
This update has been submitted for testing by limb.
bodhi - 2013-10-22 17:03:23
This update is currently being pushed to the Fedora EPEL 6 testing updates repository.
bodhi - 2013-10-22 19:06:26
This update has been pushed to testing
Anonymous Tester - 2013-10-24 15:29:55
Thanks!
mikaku - 2013-10-24 15:34:53
cicku - 2013-10-25 07:18:19
works.
lbazan - 2013-10-25 14:12:03
bodhi - 2013-10-25 14:12:07
This update has reached the stable karma threshold and will be pushed to the stable updates repository
bodhi - 2013-10-25 15:46:05
This update is currently being pushed to the Fedora EPEL 6 stable updates repository.
bodhi - 2013-10-25 17:37:55
This update has been pushed to stable

Add a comment

Tip: Login to impact how quickly this update gets pushed or unpushed.
obfuscated letters