Описание
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| roundcube | fixed | 1.5~rc+dfsg.1-1 | experimental | package |
| roundcube | fixed | 1.5.0+dfsg.1-1 | package | |
| roundcube | ignored | bullseye | package | |
| roundcube | ignored | buster | package | |
| roundcube | no-dsa | stretch | package |
Примечания
https://github.com/roundcube/roundcubemail/issues/6891
Связанные уязвимости
CVSS3: 7.4
ubuntu
больше 6 лет назад
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVSS3: 7.4
nvd
больше 6 лет назад
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVSS3: 7.4
github
больше 3 лет назад
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.