Fedora 22 : roundcubemail-1.1.2-1.fc22 (2015-11405)

high Nessus Plugin ID 85058

Synopsis

The remote Fedora host is missing a security update.

Description

**Release 1.1.2**

- Add new plugin hook 'identity_create_after' providing the ID of the inserted identity (#1490358)

- Add option to place signature at bottom of the quoted text even in top-posting mode [sig_below]

- Fix handling of %-encoded entities in mailto: URLs (#1490346)

- Fix zipped messages downloads after selecting all messages in a folder (#1490339)

- Fix vpopmaild driver of password plugin

- Fix PHP warning: Non-static method PEAR::setErrorHandling() should not be called statically (#1490343)

- Fix tables listing routine on mysql and postgres so it skips system or other database tables and views (#1490337)

- Fix message list header in classic skin on window resize in Internet Explorer (#1490213)

- Fix so text/calendar parts are listed as attachments even if not marked as such (#1490325)

- Fix lack of signature separator for plain text signatures in html mode (#1490352)

- Fix font artifact in Google Chrome on Windows (#1490353)

- Fix bug where forced extwin page reload could exit from the extwin mode (#1490350)

- Fix bug where some unrelated attachments in multipart/related message were not listed (#1490355)

- Fix mouseup event handling when dragging a list record (#1490359)

- Fix bug where preview_pane setting wasn't always saved into user preferences (#1490362)

- Fix bug where messages count was not updated after message move/delete with skip_deleted=false (#1490372)

- Fix security issue in contact photo handling (#1490379)

- Fix possible memcache/apc cache data consistency issues (#1490390)

- Fix bug where imap_conn_options were ignored in IMAP connection test (#1490392)

- Fix bug where some files could have 'executable' extension when stored in temp folder (#1490377)

- Fix attached file path unsetting in database_attachments plugin (#1490393)

- Fix issues when using moduserprefs.sh without --user argument (#1490399)

- Fix potential info disclosure issue by protecting directory access (#1490378)

- Fix blank image in html_signature when saving identity changes (#1490412)

- Installer: Use openssl_random_pseudo_bytes() (if available) to generate des_key (#1490402)

- Fix XSS vulnerability in _mbox argument handling (#1490417)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected roundcubemail package.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1241056

http://www.nessus.org/u?f0e6d6b0

Plugin Details

Severity: High

ID: 85058

File Name: fedora_2015-11405.nasl

Version: 2.6

Type: local

Agent: unix

Published: 7/29/2015

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:roundcubemail, cpe:/o:fedoraproject:fedora:22

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 7/13/2015

Reference Information

CVE: CVE-2015-5381, CVE-2015-5382, CVE-2015-5383

FEDORA: 2015-11405