Описание
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Ссылки
- Patch
- Patch
- Patch
- Patch
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.6.0 (включая) до 1.6.17 (исключая)Версия от 1.7.0 (включая) до 1.7.2 (исключая)
Одно из
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00277
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-835
Связанные уязвимости
CVSS3: 4.3
ubuntu
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
CVSS3: 4.3
debian
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite ...
CVSS3: 4.3
github
23 дня назад
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
EPSS
Процентиль: 20%
0.00277
Низкий
4.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-835