openSUSE Security Update : roundcubemail (openSUSE-SU-2015:0116-1)

medium Nessus Plugin ID 80989

Synopsis

The remote openSUSE host is missing a security update.

Description

roundcubemail was updated to 1.0.4 fixing bugs and security issues.

Changes :

- Disable TinyMCE contextmenu plugin as there are more cons than pros in using it (#1490118)

- Fix bug where show_real_foldernames setting wasn't honored on compose page (#1490153)

- Fix issue where Archive folder wasn't protected in Folder Manager (#1490154)

- Fix compatibility with PHP 5.2. in rcube_imap_generic (#1490115)

- Fix setting flags on servers with no PERMANENTFLAGS response (#1490087)

- Fix regression in SHAA password generation in ldap driver of password plugin (#1490094)

- Fix displaying of HTML messages with absolutely positioned elements in Larry skin (#1490103)

- Fix font style display issue in HTML messages with styled <span> elements (#1490101)

- Fix download of attachments that are part of TNEF message (#1490091)

- Fix handling of uuencoded messages if messages_cache is enabled (#1490108)

- Fix handling of base64-encoded attachments with extra spaces (#1490111)

- Fix handling of UNKNOWN-CTE response, try do decode content client-side (#1490046)

- Fix bug where creating subfolders in shared folders wasn't possible without ACL extension (#1490113)

- Fix reply scrolling issue with text mode and start message below the quote (#1490114)

- Fix possible issues in skin/skin_path config handling (#1490125)

- Fix lack of delimiter for recipient addresses in smtp_log (#1490150)

- Fix generation of Blowfish-based password hashes (#1490184)

- Fix bugs where CSRF attacks were still possible on some requests (CVE-2014-9587)

Solution

Update the affected roundcubemail package.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=913095

https://lists.opensuse.org/opensuse-updates/2015-01/msg00056.html

Plugin Details

Severity: Medium

ID: 80989

File Name: openSUSE-2015-58.nasl

Version: 1.5

Type: local

Agent: unix

Published: 1/26/2015

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:novell:opensuse:13.2, p-cpe:/a:novell:opensuse:roundcubemail

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 1/15/2015

Reference Information

CVE: CVE-2014-9587