Updated roundcubemail package fixes security vulnerabilities
Publication date: 13 Aug 2026Modification date: 13 Aug 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Description
Updated roundcubemail to the 1.6.17 version to fix security
vulnerabilities:
Some XSS and DoS errors have been corrected.
Various vulnerabilities in the password plugin have been fixed.
An infinite loop has been fixed.
References
- https://bugs.mageia.org/show_bug.cgi?id=35944
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TL4FNTXFDUDYFIB5CESGSLF7DCZCMJT6/
- https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54432
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54433
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62641
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62642
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62643
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62644
- https://www.cve.org/CVERecord?id=CVE-2026-54432
- https://www.cve.org/CVERecord?id=CVE-2026-54433
- https://www.cve.org/CVERecord?id=CVE-2026-62641
- https://www.cve.org/CVERecord?id=CVE-2026-62642
- https://www.cve.org/CVERecord?id=CVE-2026-62643
- https://www.cve.org/CVERecord?id=CVE-2026-62644
SRPMS
9/core
- roundcubemail-1.6.17-1.mga9