Advisories ยป MGASA-2022-0039

Updated roundcubemail packages fix security vulnerability

Publication date: 27 Jan 2022
Modification date: 27 Jan 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-44025 , CVE-2021-44026

Description

XSS in handling an attachment's filename extension when displaying a MIME
type warning message (CVE-2021-44025).
Potential SQL injection via search or search_params (CVE-2021-44026).
                

References

SRPMS

8/core