Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:0742-1

Опубликовано: 19 мар. 2017
Источник: suse-cvrf

Описание

Security update for roundcubemail

This update to roundcubemail 1.1.8 fixes security issues and bugs.

The following vulnerability was fixed:

  • CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element (boo#1029035)

The following bugs were fixed:

  • bug where mail content frame couldn't be reset in some corner cases
  • regression where groups with email address were resolved to its members' addresses
  • group/addressbook selection is retained on page refresh
  • signature couldn't be added above the quote in Firefox 51
  • microseconds macro (u) in log_date_format works

Список пакетов

openSUSE Leap 42.1
roundcubemail-1.1.8-18.1
openSUSE Leap 42.2
roundcubemail-1.1.8-18.1

Описание

rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability via a crafted Cascading Style Sheets (CSS) token sequence within an SVG element.


Затронутые продукты
openSUSE Leap 42.1:roundcubemail-1.1.8-18.1
openSUSE Leap 42.2:roundcubemail-1.1.8-18.1

Ссылки