Bug 23826 - roundcubemail new XSS security issue fixed upstream in 1.3.8 (CVE-2018-19206)
Summary: roundcubemail new XSS security issue fixed upstream in 1.3.8 (CVE-2018-19206)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-64-OK
Keywords: advisory, has_procedure, validated_update
Depends on:
Blocks:
 
Reported: 2018-11-08 19:46 CET by David Walser
Modified: 2020-09-25 00:56 CEST (History)
7 users (show)

See Also:
Source RPM: roundcubemail-1.3.6-3.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-11-08 19:46:02 CET
Fedora has issued an advisory on November 4:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/56EUDX57TIX42ULN63ZD6HCOX5PLNOZJ/

Mageia 6 is also affected.
David Walser 2018-11-08 19:46:26 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2018-11-08 23:09:24 CET
Assigning to all packagers collectively, since there is no registered maintainer for this package.

CC'ing two committers.

Assignee: bugsquad => pkg-bugs
CC: (none) => guillomovitch, marja11, mrambo

Comment 2 Mike Rambo 2018-11-15 17:08:49 CET
Updated package uploaded for cauldron and Mageia 6.

Advisory:
========================

Updated roundcubemail package fixes security vulnerability and bugs:

This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability (in handling invalid style tag content) plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot and MySQL 8 (no CVE).


References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/56EUDX57TIX42ULN63ZD6HCOX5PLNOZJ/
========================

Updated packages in core/updates_testing:
========================
roundcubemail-1.3.8-1.mga6.noarch.rpm

from roundcubemail-1.3.8-1.mga6.src.rpm


Testing procedure: https://bugs.mageia.org/show_bug.cgi?id=9640#c5

Keywords: (none) => has_procedure
Whiteboard: MGA6TOO => (none)
Assignee: pkg-bugs => qa-bugs
Version: Cauldron => 6

Comment 3 Herman Viaene 2018-11-16 15:50:31 CET
MGA6-32 MATE on IBM Thinkpad R50e
No installation issues.
Ref to bug 9640 is obsolete as roundcubemail/installer does not exist anymore.
Bug 22941 is a better guide.
But step 5 js dependencies does not exist anymore either, so I just skipped that step.
Step 7 (roundcube page) brrings me into a log screen, but there I'm stuck since I don't have any IMAP account (sticking to pop3)
But AFAICS, it looks OK.
Leaving the OK for someone with a real IMAP account.

CC: (none) => herman.viaene

Comment 4 PC LX 2018-11-19 15:32:50 CET
Installed and tested without issue.

System: Mageia 6, x86_64, Firefox, Chrome, Chromium, Plasma DE, LXQt, Intel CPU, nVidia GPU using nvidia240 proprietary driver.

For step-by-step installing instructions look here:
https://bugs.mageia.org/show_bug.cgi?id=22941#c10

$ uname -a
Linux marte 4.14.78-desktop-1.mga6 #1 SMP Sun Oct 21 20:31:12 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep roundcube
roundcubemail-1.3.6-1.2.mga6

Whiteboard: (none) => MGA6-64-OK
CC: (none) => mageia

Comment 5 Lewis Smith 2018-11-19 21:01:17 CET
(In reply to PC LX from comment #4)
> $ rpm -qa | grep roundcube
> roundcubemail-1.3.6-1.2.mga6
Thank you (& Herman) for your test of this difficult package (and the installation pointer);
but is the version right? Comment 2 says "roundcubemail-1.3.8-1.mga6".

@Herman: what version did you test?

Advisory done from c2.

CC: (none) => lewyssmith
Keywords: (none) => advisory

Comment 6 PC LX 2018-11-19 21:45:54 CET
(In reply to Lewis Smith from comment #5)
> (In reply to PC LX from comment #4)
> > $ rpm -qa | grep roundcube
> > roundcubemail-1.3.6-1.2.mga6
> but is the version right? Comment 2 says "roundcubemail-1.3.8-1.mga6".

Sorry, my mistake! I copied the version from before the update.

This is the version I tested, the one after the update.

$ rpm -qa | grep roundcubemail                                                                                                                                                   
roundcubemail-1.3.8-1.mga6
Comment 7 Lewis Smith 2018-11-20 19:49:15 CET
Thanks a bunch, PC_LX. Can validate this now (which you could have done).

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 8 Mageia Robot 2018-11-21 18:51:58 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0463.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 9 David Walser 2018-12-26 01:41:33 CET
This is CVE-2018-19206, according to this Debian advisory from November 24:
https://www.debian.org/security/2018/dsa-4344

Summary: roundcubemail new XSS security issue fixed upstream in 1.3.8 => roundcubemail new XSS security issue fixed upstream in 1.3.8 (CVE-2018-19206)

Comment 10 David Walser 2020-09-25 00:56:17 CEST
CVE-2018-19205 was also fixed in 1.3.7 in this update:
https://bugzilla.suse.com/show_bug.cgi?id=1115719
https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html

Note You need to log in before you can comment on or make changes to this bug.