Fedora 12 : roundcubemail-0.3.1-2.fc12 (2010-1385)
Medium Nessus Plugin ID 47253
SynopsisThe remote Fedora host is missing a security update.
DescriptionCommon Vulnerabilities and Exposures assigned an identifier CVE-2010-0464 to the following vulnerability: Name: CVE-2010-0464 URL:
http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2010-0464 Assigned:
20100129 Reference: MISC:
https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_W ebmail Reference: CONFIRM: http://trac.roundcube.net/ticket/1486449 Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.
Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected roundcubemail package.