Описание
Security update for roundcubemail
This update to roundcubemail 1.1.8 fixes security issues and bugs.
The following vulnerability was fixed:
- CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element (boo#1029035)
The following bugs were fixed:
- bug where mail content frame couldn't be reset in some corner cases
- regression where groups with email address were resolved to its members' addresses
- group/addressbook selection is retained on page refresh
- signature couldn't be added above the quote in Firefox 51
- microseconds macro (u) in log_date_format works
Список пакетов
openSUSE Leap 42.1
roundcubemail-1.1.8-18.1
openSUSE Leap 42.2
roundcubemail-1.1.8-18.1
Ссылки
- E-Mail link for openSUSE-SU-2017:0742-1
- SUSE Security Ratings
Описание
rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.
Затронутые продукты
openSUSE Leap 42.1:roundcubemail-1.1.8-18.1
openSUSE Leap 42.2:roundcubemail-1.1.8-18.1
Ссылки
- CVE-2017-6820
- SUSE Bug 1029035