LWN.net Logo

roundcubemail: information disclosure

Package(s):roundcubemail CVE #(s):CVE-2010-0464
Created:February 3, 2010 Updated:February 25, 2010
Description:

From the Red Hat bugzilla entry:

Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

Alerts:
Mandriva MDVSA-2010:048 2010-02-25
Fedora FEDORA-2010-1385 2010-02-02
Fedora FEDORA-2010-1399 2010-02-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds