Описание
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| roundcube | fixed | 1.1.1+dfsg.1-2 | package | |
| roundcube | not-affected | wheezy | package |
Примечания
http://trac.roundcube.net/ticket/1490261
http://advisories.mageia.org/MGASA-2015-0400.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00032.html
Связанные уязвимости
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.