Vulnerability Bulletins

DSA-4181 roundcube - security update

   
Affected software Debian
 
Andrea Basile discovered that the archive plugin in roundcube, askinnable AJAX based webmail solution for IMAP servers, does notproperly sanitize a user-controlled parameter, allowing a remoteattacker to inject arbitrary IMAP commands and perform maliciousactions.

More info:

https://www.debian.org/security/2018/dsa-4181