Advisories ยป MGASA-2016-0430

Updated roundcubemail packages fix security vulnerability

Publication date: 29 Dec 2016
Modification date: 29 Dec 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-9920

Description

Users can execute commands on the server by writing e-mails, due to
insufficient sanitation of the from field when calling PHP's mail()
function (CVE-2016-9920).

Note that only roundcubemail installations that don't have an SMTP
server configured for mail delivery are affected.
                

References

SRPMS

5/core