Software-update: Roundcube Webmail 1.6.19 / 1.7.4
Er zijn updates verschenen voor versies 1.6 en 1.7 van Roundcube Webmail die diverse beveiligensproblemen moeten verhelpen. Roundcube Webmail biedt een webinterface om e-mail te kunnen lezen en verzenden. Het heeft onder andere ondersteuning voor gedeelde mappen en namespaces, internationalized domain names en SMTP-afleverstatusnotificaties. Daarnaast is de gebruikersinterface voor IMAP-mappen aangepast om zo meer ruimte te bieden voor extensies en plug-ins. De releasenotes voor beide versies kan hieronder worden gevonden.
Security updates 1.6.19 and 1.7.4 releasedWe just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.
Security fixesFix CSS declaration smuggling via un-encoded ampersand emission, reported by Zach Hanley of Horizon3.aiFix CSS property injection via body background attribute, reported by zenithhostingevanFix email header injection via bare CR in the subject field, reported by CVE-Hunter-LeoFix email header injection via C-escape \r in the recipient display name, reported by dogesharkFix email header injection via identity’s organization field, reported by dogesharkFix zero-click stored XSS via TNEF MIME tag injection in the attachment URL, reported by nakkoFix XSS in the HTML editor using text/enriched part content, reported by Joshua RogersFix cross-user access in contact group membership (add/remove) in the SQL address book, reported by Joshua RogersFix is_local_url() bypass via trailing-dot FQDN in stylesheet URL, reported by nept1337Fix remote content blocking bypass via CSS escapes in FuncIRI attributes, reported by neoxedFix remote-content blocker bypass via SVG SMIL src animationFix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses, reported by faceless0x7 and Harish Annavisamy
Fix CSS declaration smuggling via un-encoded ampersand emission, reported by Zach Hanley of Horizon3.aiFix CSS property injection via body background attribute, reported by zenithhostingevanFix email header injection via bare CR in the subject field, reported by CVE-Hunter-LeoFix email header injection via C-escape \r in the recipient display name, reported by dogesharkFix email header injection via identity’s organization field, reported by dogesharkFix zero-click stored XSS via TNEF MIME tag injection in the attachment URL, reported by nakkoFix XSS in the HTML editor using text/enriched part content, reported by Joshua RogersFix cross-user access in contact group membership (add/remove) in the SQL address book, reported by Joshua RogersFix is_local_url() bypass via trailing-dot FQDN in stylesheet URL, reported by nept1337Fix remote content blocking bypass via CSS escapes in FuncIRI attributes, reported by neoxedFix remote-content blocker bypass via SVG SMIL src animationFix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses, reported by faceless0x7 and Harish AnnavisamySee the full changelogs in the release notes on the Github download pages for the updated versions 1.6.19 and 1.7.4. We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.
Source:
Tweakers.net