Debian alert DLA-4760-1 (roundcube)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4760-1] roundcube security update | |
| Date: | Sat, 29 Aug 2026 22:38:37 +0200 | |
| Message-ID: | <apNDSTxEsuinYROv@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4760-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin August 29, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : roundcube Version : 1.4.15+dfsg.1-1+deb11u11 1.6.5+dfsg-1+deb12u11 CVE ID : CVE-2026-74997 CVE-2026-74998 CVE-2026-74999 CVE-2026-75000 CVE-2026-75002 CVE-2026-75003 CVE-2026-75004 CVE-2026-75006 CVE-2026-75007 CVE-2026-75010 Debian Bug : 1144059 Multiple vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, server-side request forgery, information disclosure, privilege escalation, IMAP injection, account takeover, or remote code execution. CVE-2026-74997 A remote code execution vulnerability was found in the "cmd_learn" learning driver of the "markasjunk" plugin. Placeholders such as %u (username), %l (localpart) and %d (domainpart) were injected with insufficiently sanitized/escaped values used within a `sh -c '…'` shell construction, thereby allowing remote code execution from the user used to run roundcube (by default www-data). Only installations where 1/ the "markasjunk" plugin was enabled, and 2/ where the `$config['markasjunk_learning_driver']` setting was set to `"cmd_learn"`, were affected by this vulnerability. In particular, stock installations were not affected since the plugin is not enabled by default. CVE-2026-74998 Content proxied by the CSS proxy (which is used to retrieve remote style sheets linked to in text/html emails) was found to be lacking basic validation, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. CVE-2026-74999 Paulos Yibelo discovered that the “Add to address book” action was subject to stored XSS due to insufficient sanitization of error messages and information popups. CVE-2026-75000 Insufficient HTML/CSS sanitization may lead to remote image blocking bypass or XSS via crafted SVG animate `by` attribute sent in malicious text/html emails. CVE-2026-75002 Zach Hanley discovered that mail search and RFC2088 IMAP4 LITERAL+ byte-count desynchronization may lead to IMAP command injection. CVE-2026-75003 Milan Hoppe discovered that insufficient HTML/CSS sanitization may lead to remote image blocking bypass or XSS via unclosed url() in a FuncIRI attribute. CVE-2026-75004 Milan Hoppe discovered that managesieve rule names were not sanitized, thereby allowing arbitrary sieve injection and bypass of the "managesieve_disabled_actions" restriction set by an administrator. This vulnerability only affects installations where the "managesieve" plugin is enabled. In particular, stock installations were not affected since the plugin is not enabled by default. CVE-2026-75006 Dmytro Ivanenko and Milan Hoppe discovered that that the CSS sanitization fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643 were insufficient, allowing a malicious embedded stylesheet in a text/html email to lead to SSRF or information disclosure. CVE-2026-75007 Milan Hoppe discovered that the LDAP integration was subject to filter injection via unescaped %u/%fu/%d substitution. CVE-2026-75010 The "modoba" driver of the "password" plugin was found to be leaking an authentication token, which may lead to account takeover. Only installations where 1/ the "password" plugin was enabled, and 2/ where the `$config['password_driver']` setting was set to `"modoboa"`, were affected by this vulnerability. In particular, stock installations were not affected since the "password" plugin is not enabled by default. For Debian 11 bullseye, these problems have been fixed in version 1.4.15+dfsg.1-1+deb11u11. For Debian 12 bookworm, these problems have been fixed in version 1.6.5+dfsg-1+deb12u11. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/roundcube Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmqTQ0oACgkQ05pJnDwh pVJmVBAAsAFSnD+QYOGKlCNHfO1Kg9MBKkL+fN+RqAVoeFIDoQ3WHD/VRfh3n7cC l/Bv442O3jQDX9kNQkBfMk3te99+1wP3yWGF4iwSd6Z5G0+nhD0IwkCJ0awXA/Df Soqre07JqhPIMECPBkr+zbDkf/lMSOWRr3QPX23QB8kiUMI6DKMcPnOho61+UpZ0 TIzS4lsW3CeesacRzw25cWD3sLSn2JV8jR641f0pz89wHZLD7wzIqwwNfhw0OmVF S7Yu6H9nneL8stUHg3dgKqUvYCAJYNW48njETCwruwDU6bHAHchOjFP/9Z34cJWU LI4X2D9ac3VkbyPjxgWKkKT+7MVnYMC1bj7nNyQzZiPb64pfXJYBXCAdcvPYWXZJ Bu5sYDeFhUNwMgXp0fyVNT7U3+O66Iy85Wy5Pi5kFZODzcOiVaA4BV5BwgtTxzMz iIkSRwoReIe2GOxMdsOor0TK37kn5sjh+xIpOe6FQrrpNzJTgs8HI8z2AIzf6CNo rgwWrNq2WDcxzg5sJxJLd3YnV217rVDFgWk9X4lP9iOQYwaJp4qV311QYO6UxE9q jsyzZc4BL4GRIfgJv7x9Zf9nHgNMMVkL0+CgoZRpRoIMUOADOtxcEPu2iZ91BddS lh9dQx1sPBYThO0TbPUEm5xvfOk+1RQqQXHfAyrvDfgKHG+Xmt8= =jpgH -----END PGP SIGNATURE-----
