Fedora 15 : roundcubemail-0.5.1-1.fc15 (2011-4038)

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

Roundcube Webmail upstream has released v0.5.1 version: [1]
http://trac.roundcube.net/wiki/Changelog

which adds one security hardening: 1), Security: add optional referer
check to prevent CSRF in GET requests Relevant patches: [2]
http://trac.roundcube.net/changeset/4503 [3]
http://trac.roundcube.net/changeset/4504

and fixes two security flaws: 2), Security: protect login form
submission from CSRF Relevant patch: [4]
http://trac.roundcube.net/changeset/4490 3), Security: prevent from
relaying malicious requests through modcss.inc Relevant patch: [5]
http://trac.roundcube.net/changeset/4488

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://roundcube.net/news
http://sourceforge.net/news/?group_id=139281&id=297236
http://trac.roundcube.net/changeset/4488
http://trac.roundcube.net/changeset/4490
http://trac.roundcube.net/changeset/4503
http://trac.roundcube.net/changeset/4504
http://trac.roundcube.net/wiki/Changelog
http://www.openwall.com/lists/oss-security/2011/03/24/3
http://www.nessus.org/u?c9143218

Solution :

Update the affected roundcubemail package.

Risk factor :

High

Family: Fedora Local Security Checks

Nessus Plugin ID: 53201 ()

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now