Oval Definition:oval:org.opensuse.security:def:20158770
Revision Date:2022-06-30Version:1
Title:CVE-2015-8770
Description:

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-8770
Mitre CVE-2015-8770
SUSE CVE-2015-8770
openSUSE-SU-2016:0210-1
openSUSE-SU-2016:0213-1
openSUSE-SU-2016:0214-1
Platform(s):openSUSE 13.1
openSUSE 13.2
openSUSE Leap 42.1
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE 13.1 is installed
  • AND roundcubemail-1.0.8-2.27.1 is installed
  • Definition Synopsis
  • openSUSE 13.2 is installed
  • AND roundcubemail-1.0.8-17.1 is installed
  • Definition Synopsis
  • openSUSE Leap 42.1 is installed
  • AND Package Information
  • roundcubemail-1.1.4-6.1 is installed
  • AND roundcubemail is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND roundcubemail-1.2.3-1.1 is installed
  • BACK