Oval Definition:oval:org.mitre.oval:def:19395
Revision Date:2014-06-23Version:6
Title:DSA-2787-1 roundcube - design error
Description:It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, does not properly sanitise the _session parameter in steps/utils/save_pref.inc during saving preferences. The vulnerability can be exploited to overwrite configuration settings and subsequently allowing random file access, manipulated SQL queries and even code execution.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-6172
DSA-2787-1
Platform(s):Debian GNU/kFreeBSD 7
Debian GNU/Linux 7
Product(s):roundcube
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND roundcube DPKG is earlier than 0:0.7.2-9+deb7u1
  • BACK