सुरक्षा सलाह पर वापस जाएँ

Roundcube 1.7.1 CVE

High
DirectAdmin

प्रभावित संस्करण

1.7.1

डिफ़ॉल्ट अपडेट कमांड

cd /usr/local/directadmin/custombuild && ./build update_versions

Security updates 1.6.16 and 1.7.1 released

We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.

Security fixes

  • Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog
  • Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName=”style”>
  • Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass
  • Fix SSRF bypass via specific local address URLs
  • Fix local/private URL fetch bypass when remote resources were not allowed
  • Fix bypass of remote image blocking via CSS var()
  • Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass
  • Fix code injection vulnerability – remove support for code evaluation in LDAP autovalues option

See the full changelogs in the release notes on the Github download pages for the updated versions 1.6.16 and 1.7.1. We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें