Software-update: Roundcube Webmail 1.6.18 / 1.7.3
Er zijn updates verschenen voor versies 1.6 en 1.7 van Roundcube Webmail die diverse beveiligensproblemen moeten verhelpen. Roundcube Webmail biedt een webinterface om e-mail te kunnen lezen en verzenden. Het heeft onder andere ondersteuning voor gedeelde mappen en namespaces, internationalized domain names en SMTP-afleverstatusnotificaties. Daarnaast is de gebruikersinterface voor IMAP-mappen aangepast om zo meer ruimte te bieden voor extensies en plug-ins. De changelog voor beide versies kan hieronder worden gevonden.
Security updates 1.6.18 and 1.7.3 releasedWe just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.
Add basic validation for content proxied by the css proxyFix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 netsFix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() checkFix remote content blocking bypass via unclosed url() in a FuncIRI attributeFix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filterFix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actionsFix RCE via cmd_learn driver of markasjunk pluginFix IMAP command injection via mail search and LITERAL+ byte-count desynchronizationFix password’s modoboa driver leak of an authentication token to a user-controlled hostFix stored XSS in “Add to address book” actionFix HTML/CSS sanitization bypass via SVG animate by attribute
Add basic validation for content proxied by the css proxyFix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 netsFix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() checkFix remote content blocking bypass via unclosed url() in a FuncIRI attributeFix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filterFix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actionsFix RCE via cmd_learn driver of markasjunk pluginFix IMAP command injection via mail search and LITERAL+ byte-count desynchronizationFix password’s modoboa driver leak of an authentication token to a user-controlled hostFix stored XSS in “Add to address book” actionFix HTML/CSS sanitization bypass via SVG animate by attributeSee the full changelogs in the release notes on the Github download pages for the updated versions 1.6.18 and 1.7.3. We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.
Source:
Tweakers.net