FreeBSD Bugzilla – Attachment 192465 Details for
Bug 227476
mail/roundcube: Update to 1.3.6 (a security update for CVE-2018-9846
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
patch-updates-vuxml.diff
patch-roundcube.vuxml.diff (text/plain), 1.37 KB, created by
Mahdi Mokhtari
on 2018-04-12 16:53:13 UTC
(
hide
)
Description:
patch-updates-vuxml.diff
Filename:
MIME Type:
Creator:
Mahdi Mokhtari
Created:
2018-04-12 16:53:13 UTC
Size:
1.37 KB
patch
obsolete
>Index: vuln.xml >=================================================================== >--- vuln.xml (revision 467162) >+++ vuln.xml (working copy) >@@ -58,6 +58,35 @@ > * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="48894ca9-3e6f-11e8-92f0-f0def167eeea"> >+ <topic>roundcube -- IMAP command injection vulnerability</topic> >+ <affects> >+ <package> >+ <name>roundcube</name> >+ <range><le>1.3.5,1</le></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Upstream reports:</p> >+ <blockquote cite="https://roundcube.net/news/2018/04/11/security-update-1.3.6"> >+ <p>This update primarily fixes a recently discovered IMAP-cmd-injection >+ vulnerability caused by insufficient input validation within >+ the archive plugin. >+ Details about the vulnerability are published under CVE-2018-9846.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2018-9846</cvename> >+ <url>https://roundcube.net/news/2018/04/11/security-update-1.3.6</url> >+ </references> >+ <dates> >+ <discovery>2018-04-11</discovery> >+ <entry>2018-04-12</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="5c6f7482-3ced-11e8-b157-6451062f0f7a"> > <topic>Flash Player -- multiple vulnerabilities</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Flags:
riggs
:
maintainer-approval+
Actions:
View
|
Diff
Attachments on
bug 227476
:
192464
| 192465