Fedora 31 : roundcubemail (2020-5352732865)

high Nessus Plugin ID 138478

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**RELEASE 1.4.7**

- Fix bug where subfolders of special folders could have been duplicated on folder list

- Increase maximum size of contact jobtitle and department fields to 128 characters

- Fix missing newline after the logged line when writing to stdout (#7418)

- Elastic: Fix context menu (paste) on the recipient input (#7431)

- Fix problem with forwarding inline images attached to messages with no HTML part (#7414)

- Fix problem with handling attached images with same name when using database_attachments/redundant_attachments (#7455)

- **Security**: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected roundcubemail package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2020-5352732865

Plugin Details

Severity: High

ID: 138478

File Name: fedora_2020-5352732865.nasl

Version: 1.1

Type: local

Agent: unix

Published: 7/15/2020

Updated: 7/15/2020

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:31, p-cpe:/a:fedoraproject:fedora:roundcubemail

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 7/15/2020

Vulnerability Publication Date: 7/15/2020

Reference Information