Updated roundcubemail packages fix security vulnerability
Publication date: 29 Dec 2016Modification date: 29 Dec 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-9920
Description
Users can execute commands on the server by writing e-mails, due to insufficient sanitation of the from field when calling PHP's mail() function (CVE-2016-9920). Note that only roundcubemail installations that don't have an SMTP server configured for mail delivery are affected.
References
SRPMS
5/core
- roundcubemail-1.0.9-1.1.mga5