Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8114

Опубликовано: 29 апр. 2017
Источник: debian

Описание

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.2.3+dfsg.1-4package

Примечания

  • https://github.com/roundcube/roundcubemail/releases/tag/1.2.5

  • https://github.com/roundcube/roundcubemail/commit/6e054a37d13dc3772d0aa454a32d5dc3bdcc7003 (1.2.x)

  • https://github.com/roundcube/roundcubemail/releases/tag/1.1.9

  • https://github.com/roundcube/roundcubemail/commit/10b227d70a03e33682aaaa0138e84f9256f3cd50 (1.1.x)

  • https://github.com/roundcube/roundcubemail/releases/tag/1.0.11

  • https://github.com/roundcube/roundcubemail/commit/271426429bfbb5b63e6dec91b1e4780e8ef1c67e (1.0.x)

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

CVSS3: 8.8
nvd
почти 9 лет назад

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

suse-cvrf
больше 8 лет назад

Security update for roundcubemail

CVSS3: 8.8
github
больше 3 лет назад

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.