USN-7200-1: Roundcube vulnerability
13 January 2025
Roundcube could be made to expose sensitive information.
Releases
Packages
- roundcube - skinnable AJAX based webmail solution for IMAP servers - metapack
Details
It was discovered that Roundcube incorrectly handled certain file-based
attachment plugins. An attacker could exploit this to gain unauthorized
access to arbitrary files on the host’s file system.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
roundcube-core
-
1.2~beta+dfsg.1-0ubuntu1+esm5
Available with Ubuntu Pro
-
roundcube-plugins
-
1.2~beta+dfsg.1-0ubuntu1+esm5
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.