openSUSE Security Update : roundcubemail (openSUSE-2017-580)
Medium Nessus Plugin ID 100203
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis update for roundcubemail fixes one security issues and two bugs.
The following vulnerability was fixed :
- CVE-2017-8114: Authenticated users may have reset arbitrary passwords (boo#1036955)
The following upstream bugs were fixed :
- Fix regression in LDAP fuzzy search where it always used prefix search instead
- Fix bug where base_dn setting was ignored inside group_filters
SolutionUpdate the affected roundcubemail package.