Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 488994 - <mail-client/roundcube-{0.8.7,0.9.5}: random file access, manipulated SQL queries and even code execution (CVE-2013-6172)
Summary: <mail-client/roundcube-{0.8.7,0.9.5}: random file access, manipulated SQL que...
Status: RESOLVED DUPLICATE of bug 488954
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: http://roundcube.net/news/2013/10/21/...
Whiteboard: B1 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-22 11:20 UTC by Alex Xu (Hello71)
Modified: 2013-10-22 12:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Xu (Hello71) 2013-10-22 11:20:08 UTC
We just published new releases which fix a recently reported vulnerability that allows an attacker to overrwrite configuration settings using user preferences. This can result in random file access, manipulated SQL queries and even code execution. The latter one only affects versions 0.8.6 and older.

[ ... ]

More information about this vulnerability will be published under CVE-2013-6172.
Comment 1 Agostino Sarubbo gentoo-dev 2013-10-22 12:23:50 UTC

*** This bug has been marked as a duplicate of bug 488954 ***