Bug 952007 - Tracker bug for roundcubemail (13.2)
Summary: Tracker bug for roundcubemail (13.2)
Status: RESOLVED DUPLICATE of bug 952006
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P5 - None : Normal
Target Milestone: unspecified
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-26 12:28 UTC by Aeneas Jaißle
Modified: 2015-10-26 13:21 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aeneas Jaißle 2015-10-26 12:28:19 UTC
Tracker bug for roundcubemail.
Comment 1 Aeneas Jaißle 2015-10-26 12:48:12 UTC
https://build.opensuse.org/request/show/340988


This update fixes one security issue and one bug.

roundcubemail was updated to disallow unwanted access on files in the file system.
The apache2 configuration file for roundcubemail allowed access to the roundcubemail/bin folder and possibly /logs, /config and /temp, if these were not symlinks (this is only the case when manually changed).

This update comes with a fixed configuration. If you modified the file "/etc/apache2/conf.d/roundcubemail.conf", please replace it with the configuration "roundcubemail.conf.rpmnew" and reapply your changes. After that, a restart of apache2 is requried.

This update also fixes an issue that causes apache2 not to start because "mod_version.c" is not loaded.
Comment 3 Aeneas Jaißle 2015-10-26 13:20:07 UTC
Btw it's all packaging updates, the upstream roundcubemail source has *not* changed.
Comment 4 Andreas Stieger 2015-10-26 13:21:01 UTC
tracking incident for all in bug 952006

*** This bug has been marked as a duplicate of bug 952006 ***