Описание
Security update for roundcubemail
This update for roundcubemail fixes the following issues:
Changes in roundcubemail:
- update to 1.6.16
- Fix potential too long value in IMAP ID command (#10136)
- Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]
- Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336]
- Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]
- Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]
- Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]
- Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]
- Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]
- Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332]
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1266329
- SUSE Bug 1266331
- SUSE Bug 1266332
- SUSE Bug 1266333
- SUSE Bug 1266334
- SUSE Bug 1266335
- SUSE Bug 1266336
- SUSE Bug 1266337
- SUSE CVE CVE-2026-48842 page
- SUSE CVE CVE-2026-48843 page
- SUSE CVE CVE-2026-48844 page
- SUSE CVE CVE-2026-48845 page
- SUSE CVE CVE-2026-48846 page
- SUSE CVE CVE-2026-48847 page
- SUSE CVE CVE-2026-48848 page
- SUSE CVE CVE-2026-48849 page
Описание
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
Затронутые продукты
Ссылки
- CVE-2026-48842
- SUSE Bug 1266329
Описание
Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.
Затронутые продукты
Ссылки
- CVE-2026-48843
- SUSE Bug 1266331
Описание
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
Затронутые продукты
Ссылки
- CVE-2026-48844
- SUSE Bug 1266332
Описание
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.
Затронутые продукты
Ссылки
- CVE-2026-48845
- SUSE Bug 1266333
Описание
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.
Затронутые продукты
Ссылки
- CVE-2026-48846
- SUSE Bug 1266334
Описание
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
Затронутые продукты
Ссылки
- CVE-2026-48847
- SUSE Bug 1266335
Описание
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
Затронутые продукты
Ссылки
- CVE-2026-48848
- SUSE Bug 1266336
Описание
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
Затронутые продукты
Ссылки
- CVE-2026-48849
- SUSE Bug 1266337