Описание
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
Ссылки
- Patch
- Patch
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.6.0 (включая) до 1.6.17 (исключая)Версия от 1.7.0 (включая) до 1.7.2 (исключая)
Одно из
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00252
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-770
Связанные уязвимости
CVSS3: 4.3
ubuntu
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
CVSS3: 4.3
debian
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF de ...
CVSS3: 4.3
github
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
EPSS
Процентиль: 17%
0.00252
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-770