Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19205

Опубликовано: 12 нояб. 2018
Источник: debian

Описание

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.3.8+dfsg.1-1package
roundcubeignoredstretchpackage

Примечания

  • https://roundcube.net/news/2018/07/27/update-1.3.7-released

  • https://github.com/roundcube/roundcubemail/issues/6289

  • https://github.com/roundcube/roundcubemail/commit/94da947855329c5062ec2a7098eb86fb675aac37 (release-1.3)

  • https://github.com/roundcube/roundcubemail/commit/2fa112bd836e5e144e270bda11c9fda1a66a22ae (master)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

CVSS3: 7.5
nvd
около 7 лет назад

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

CVSS3: 7.5
github
больше 3 лет назад

Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.