Advisories ยป MGASA-2015-0400

Updated roundcubemail package fixes security vulnerabilities

Publication date: 14 Oct 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-2180 , CVE-2015-2181 , CVE-2015-5382


Multiple security issues in the DBMail driver for the password plugin,
including buffer overflows (CVE-2015-2181) and the ability for a remote
attacker to execute arbitrary shell commands as root (CVE-2015-2180).

An authenticated user can download arbitrary files from the web server
that the web server process has read access to, by uploading a vCard with
a specially crafted POST (CVE-2015-5382).

The roundcubemail package has been updated to version 1.0.6, fixing these
issues and several other bugs, however the installer is currently known
to be broken.