Fedora 29 : roundcubemail (2019-d9c2f1ec70)

high Nessus Plugin ID 128580

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**Version 1.3.10**

- Managesieve: Fix so 'Create filter' option does not show up when Filters menu is disabled (#6723)

- Enigma: Fix bug where revoked users/keys were not greyed out in key info

- Enigma: Fix error message when trying to encrypt with a revoked key (#6607)

- Enigma: Fix 'decryption oracle' bug [CVE-2019-10740] (#6638)

- Fix compatibility with kolab/net_ldap3 > 1.0.7 (#6785)

- Fix bug where bmp images couldn't be displayed on some systems (#6728)

- Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp (#6744)

- Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758)

- Fix bug in rcube_utils::parse_hosts() where %t, %d, %z could return only tld (#6746)

- Fix bug where Next/Prev button in mail view didn't work with multi-folder search result (#6793)

- Fix bug where selection of columns on messages list wasn't working

- Fix bug in converting multi-page Tiff images to Jpeg (#6824)

- Fix wrong messages order after returning to a multi-folder search result (#6836)

- Fix PHP 7.4 deprecation: implode() wrong parameter order (#6866)

- Fix bug where it was possible to bypass the position:fixed CSS check in received messages (#6898)

- Fix bug where some strict remote URIs in url() style were unintentionally blocked (#6899)

- Fix bug where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class (#6897)

- Fix bug where it was possible to bypass href URI check with data:application/xhtml+xml URIs (#6896)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected roundcubemail package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-d9c2f1ec70

Plugin Details

Severity: High

ID: 128580

File Name: fedora_2019-d9c2f1ec70.nasl

Version: 1.4

Type: local

Agent: unix

Published: 9/9/2019

Updated: 4/26/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2019-15237

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:29, p-cpe:/a:fedoraproject:fedora:roundcubemail

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/8/2019

Vulnerability Publication Date: 4/7/2019

Reference Information

CVE: CVE-2019-10740, CVE-2019-15237