Bugzilla – Bug 913095
VUL-0: CVE-2014-9587: roundcubemail: possible CSRF attacks to some address book operations as well as to the ACL and Managesieve plugins
Last modified: 2015-07-06 11:59:42 UTC
rh#1179780 Version 1.0.4 of Roundcube contains a security fix: ... Security: Fix possible CSRF attacks to some address book operations as well as to the ACL and Managesieve plugins. ... Upstream commit: https://github.com/roundcube/roundcubemail/commit/376cbfd4f2dfcf455717409b70d9d056cbeb08b1 References: https://bugzilla.redhat.com/show_bug.cgi?id=1179780 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9587 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9587
bugbot adjusting priority
13,2 fix was submitted. 13.1 not yet
openSUSE-SU-2015:0116-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 913095 CVE References: CVE-2014-9587 Sources used: openSUSE 13.2 (src): roundcubemail-1.0.4-4.1
Can we please get a submit for 13.1?
For 13.1 this was fixed with update to 1.0.5 for bug 915789, closing.