| Summary: | roundcubemail new security issue CVE-2017-8114 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, herman.viaene, lewyssmith, marja11, mhrambo3501, sysadmin-bugs |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | advisory MGA5-32-OK MGA5-64-OK | ||
| Source RPM: | roundcubemail-1.0.9-1.2.mga5.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-05-05 20:48:00 CEST
Assinging to all packagers collectively, since there is no registered maintainer for roundcubemail CC:
(none) =>
marja11 openSUSE has issued an advisory for this today (May 15): https://lists.opensuse.org/opensuse-updates/2017-05/msg00039.html Patched package uploaded for Mageia 5. Advisory: ======================== Updated roundcubemail package fixes security vulnerability: It was discovered that roundcubemail prior to 1.0.11 contained a vulnerability in the virtualmin and sasl drivers of the password plugin (CVE-2017-8114) References: https://roundcube.net/news/2017/04/28/security-updates-1.2.5-1.1.9-and-1.0.11 https://www.suse.com/security/cve/CVE-2017-8114/ ======================== Updated packages in core/updates_testing: ======================== roundcubemail-1.0.11-1.mga5.noarch.rpm from roundcubemail-1.0.11-1.mga5.src.rpm Testing procedure: https://bugs.mageia.org/show_bug.cgi?id=9640#c5 CC:
(none) =>
mrambo
Dave Hodgins
2017-06-18 07:56:33 CEST
CC:
(none) =>
davidwhodgins MGA5-32 on Asus A 6000 VM Xfce No installation issues Ref. to bug 20463 Comment 5 and bug 9640, we're still in the same mess. After configuring all correctly, I still run in 'Database connection failure' and 'Error 404 Object not found. But ir does not seem to break anything else. CC:
(none) =>
herman.viaene Testing Mageia 5 64-bit Already installed and configured as per https://bugs.mageia.org/show_bug.cgi?id=19920#c2 roundcubemail-1.0.9-1.2.mga5 UPDATE was clean, no config file changes, to: roundcubemail-1.0.11-1.mga5 afte which http://localhost/roundcubemail/ gave our usual Roundcube error page: "DATABASE ERROR: CONNECTION FAILED! Unable to connect to the database! Please contact your server-administrator." OK as per our routine updates for this pkg. Validating. Whiteboard:
advisory MGA5-32-OK =>
advisory MGA5-32-OK MGA5-64-OK An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0181.html Resolution:
(none) =>
FIXED |