Updated roundcubemail packages fix security vulnerability
Publication date: 16 Nov 2017Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-16651
Description
It was discovered that roundcubemail contained a zero-day file disclosure vulnerability caused by insuficient input validation which was currently being exploited by hackers to read roundcube's configuration files and steal its database credentials (CVE-2017-16651).
References
SRPMS
5/core
- roundcubemail-1.0.11-1.1.mga5
6/core
- roundcubemail-1.2.5-1.1.mga6