Fedora 27 : roundcubemail (2018-d527206a77)
High Nessus Plugin ID 118725
SynopsisThe remote Fedora host is missing a security update.
This is a service release to update the stable version 1.3 of
Roundcube Webmail. It contains fixes to several bugs backported from
the master branch including a security fix for a reported XSS
vulnerability plus updates to ensure compatibility with PHP 7.3 and
recent versions of Courier-IMAP, Dovecot and MySQL 8. See the complete
- Fix PHP warnings on dummy QUOTA responses in
Courier-IMAP 4.17.1 (#6374)
- Fix so fallback from BINARY to BODY FETCH is used also
on [PARSE] errors in dovecot 2.3 (#6383)
- Enigma: Fix deleting keys with authentication subkeys
- Fix invalid regular expressions that throw warnings on
PHP 7.3 (#6398)
- Fix so Classic skin splitter does not escape out of
- Fix XSS issue in handling invalid style tag content
- Fix compatibility with MySQL 8 - error on 'system' table
- Managesieve: Fix bug where show_real_foldernames setting
wasn't respected (#6422)
- New_user_identity: Fix %fu/%u vars substitution in user
specific LDAP params (#6419)
- Fix support for 'allow-from <uri>' in 'x_frame_options'
config option (#6449)
- Fix bug where valid content between HTML comments could
have been skipped in some cases (#6464)
- Fix multiple VCard field search (#6466)
- Fix session issue on long running requests (#6470)
Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as
possible without introducing additional issues.
SolutionUpdate the affected roundcubemail package.