Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20852-1

Опубликовано: 31 мая 2026
Источник: suse-cvrf

Описание

Security update for roundcubemail

This update for roundcubemail fixes the following issues:

Changes in roundcubemail:

  • update to 1.6.16
    • Fix potential too long value in IMAP ID command (#10136)
    • Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]
    • Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336]
    • Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]
    • Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]
    • Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]
    • Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]
    • Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]
    • Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332]

Список пакетов

openSUSE Leap 16.0
roundcubemail-1.6.16-bp160.1.1

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки

Описание

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.


Затронутые продукты
openSUSE Leap 16.0:roundcubemail-1.6.16-bp160.1.1

Ссылки