LWN.net Logo

roundcubemail: cross-site scripting

Package(s):roundcubemail CVE #(s):CVE-2012-3507 CVE-2012-3508
Created:August 29, 2012 Updated:October 11, 2012
Description: From the CVE entries:

Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML via the email message subject. (CVE-2012-3507)

Cross-site scripting (XSS) vulnerability in program/lib/washtml.php in Roundcube Webmail 0.8.0 allows remote attackers to inject arbitrary web script or HTML by using "javascript:" in an href attribute in the body of an HTML-formatted email. (CVE-2012-3508)

Alerts:
Fedora FEDORA-2012-12362 2012-08-28
Fedora FEDORA-2012-12357 2012-08-28
openSUSE openSUSE-SU-2012:1124-1 2012-09-06
Mageia MGASA-2012-0292 2012-10-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds