Bug 32450 - roundcube: security update 1.6.4
Summary: roundcube: security update 1.6.4
Status: RESOLVED DUPLICATE of bug 32493
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-27 01:33 CEST by Marc Krämer
Modified: 2023-11-05 23:54 CET (History)
1 user (show)

See Also:
Source RPM: roundcube
CVE: CVE-2023-5631
Status comment:


Attachments

Description Marc Krämer 2023-10-27 01:33:54 CEST
An XSS vulnerability was found 
https://roundcube.net/news/2023/10/16/security-update-1.6.4-released
Marc Krämer 2023-10-27 01:34:14 CEST

CVE: (none) => CVE-2023-5631

Comment 1 Marc Krämer 2023-10-27 01:45:07 CEST
Updated roundcubemail fix vulnerability.
Fix cross-site scripting (XSS) vulnerability in handling of SVG in HTML messages.

References:
https://roundcube.net/news/2023/10/16/security-update-1.6.4-released
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5631
========================

Updated packages in core/updates_testing:
========================
roundcubemail-1.6.4-1.mga9.noarch.rpm

SRPM:
roundcubemail-1.6.4-1.mga9.src.rpm

Assignee: mageia => qa-bugs

Comment 2 Marja Van Waes 2023-10-27 11:43:02 CEST
Advisory from comment 1 added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete"

CC: (none) => marja11
Keywords: (none) => advisory

Comment 3 Marja Van Waes 2023-11-05 13:27:51 CET
Setting this report to depend on 32493, because that later roundcubemail update landed in updates_testing, and this one is gone.

Depends on: (none) => 32493

Marja Van Waes 2023-11-05 22:50:41 CET

Depends on: 32493 => (none)

Comment 4 Marja Van Waes 2023-11-05 22:57:20 CET
Closing as OLD because there is already bug 32493 for a newer roundcubemail package

Resolution: (none) => OLD
Status: NEW => RESOLVED
Keywords: advisory => (none)

Comment 5 David Walser 2023-11-05 23:54:51 CET
Improper resolution.  Typically we'd just leave this blocked and mark it fixed when the other one is.  Marking as a dup which will also maintain the linkage between the two bugs.

*** This bug has been marked as a duplicate of bug 32493 ***

Resolution: OLD => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.