[arch-security] [ASA-201711-27] roundcubemail: arbitrary filesystem access
foxboron at archlinux.org
Tue Nov 21 21:20:01 UTC 2017
Arch Linux Security Advisory ASA-201711-27
Date : 2017-11-21
CVE-ID : CVE-2017-16651
Package : roundcubemail
Type : arbitrary filesystem access
Remote : Yes
Link : https://security.archlinux.org/AVG-506
The package roundcubemail before version 1.3.3-1 is vulnerable to
arbitrary filesystem access.
Upgrade to 1.3.3-1.
# pacman -Syu "roundcubemail>=1.3.3-1"
The problem has been fixed upstream in version 1.3.3.
Roundcube Webmail 1.3.x before 1.3.3 allows unauthorized access to
arbitrary files on the host's filesystem, including configuration
files, as exploited in the wild in November 2017. The attacker must be
able to authenticate at the target system with a valid
username/password as the attack requires an active session. The issue
is related to file-based attachment plugins and
A remote authenticated non-admin user is able to read arbitrary files
on the affected host.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-security