Bug 34341 - Roundcubemail: Security issue
Summary: Roundcubemail: Security issue
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
: 34334 (view as bug list)
Depends on:
Blocks:
 
Reported: 2025-06-03 14:42 CEST by Marc Krämer
Modified: 2025-06-11 19:44 CEST (History)
5 users (show)

See Also:
Source RPM: roundcubemail
CVE: CVE-2025-49113
Status comment:


Attachments

Comment 1 Marc Krämer 2025-06-03 14:53:54 CEST
A Post-Auth RCE was announced and fixed in the latest release.


https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10



Files in core/updates_testing:
roundcubemail-1.6.11-1.mga9.noarch.rpm


SRPM:

roundcubemail-1.6.11-complete.tar.gz

Assignee: mageia => qa-bugs

Comment 2 Nicolas Salguero 2025-06-03 14:57:31 CEST
*** Bug 34334 has been marked as a duplicate of this bug. ***

CC: (none) => nicolas.salguero

Marc Krämer 2025-06-03 15:00:47 CEST

CVE: (none) => CVE-2025-49113

Comment 4 Nicolas Salguero 2025-06-03 16:07:02 CEST
Debian has issued an advisory on June 2:
https://lists.debian.org/debian-security-announce/2025/msg00098.html
katnatek 2025-06-04 01:17:25 CEST

Keywords: (none) => advisory

Comment 5 Herman Viaene 2025-06-04 16:12:10 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
No initial installation problems.
In the list of updates there is no link to the previous updates, annoying.
Found the QA procedure, but it is not clear to me if dovecot is really needed or not, but it is certainly not included in the dependencies.
Made changes as indicated on /etc/roundcubemail/config.inc.php with the remark that there is no 'default_host', it seems to be 'imap_host'.
Run the installation script for mysql in phpmyadmin, seems to work OK.
Then used http://localhost/roundcubemail/installer and got twp problems:
1. Connection to mysql not found. The link to the manuals told me that php-pdo_mysql was missing. Installed that one, refresh the page and this error is gone.
2. php extension Ctype:  NOT OK(See https://www.php.net/manual/en/book.ctype.php), but the manual tells me that "This extension is enabled by default. "
And that's it ....

CC: (none) => herman.viaene

Comment 6 Marc Krämer 2025-06-04 16:17:29 CEST
@Herman: I can see, if I can add those dependencies, but I must see, if this can be done easily, as this package is in noarch
Comment 7 Marc Krämer 2025-06-06 00:09:59 CEST
fixed requirements: roundcubemail-1.6.11-2.mga9.src.rpm
katnatek 2025-06-06 01:17:53 CEST

Source RPM: riundcubemail => roundcubemail

PC LX 2025-06-06 01:39:45 CEST

CC: (none) => mageia

Comment 8 PC LX 2025-06-08 13:16:32 CEST
Installed and tested three days without issues.

Tested with:
- Apache, PHP-FPM, MariaDB and Dovecot;
- PHP 8.4.7 from the backport repositories;
- Large email accounts, with GiB of emails;
- 2FA enabled using a 3rd party plugin: roundcubemail-plugin-twofactor_gauthenticator
All OK.



System: Mageia 9, x86_64, Intel(R) Core(TM) i5-4590 CPU @ 3.30GHz.



$ uname -a
Linux marte 6.6.92-server-1.mga9 #1 SMP PREEMPT_DYNAMIC Thu May 22 19:00:17 UTC 2025 x86_64 GNU/Linux
$ rpm -qa | grep roundcubemail
roundcubemail-1.6.11-2.mga9
$ php --version
PHP 8.4.7 (cli) (built: May 20 2025 21:37:25) (ZTS)
Copyright (c) The PHP Group
Zend Engine v4.4.7, Copyright (c) Zend Technologies
    with Zend OPcache v8.4.7, Copyright (c), by Zend Technologies
    with Xdebug v3.4.1, Copyright (c) 2002-2025, by Derick Rethans
Comment 9 katnatek 2025-06-11 05:29:04 CEST
(In reply to Herman Viaene from comment #5)
If you are happy with the new package, we can validate
Comment 10 Herman Viaene 2025-06-11 08:52:08 CEST
OK, go on.
Comment 11 PC LX 2025-06-11 10:24:31 CEST
With Herman and my OK, giving it the OK for x86_64.

Whiteboard: (none) => MGA9-64-OK

Comment 12 Thomas Andrews 2025-06-11 14:58:33 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 13 Mageia Robot 2025-06-11 19:44:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0185.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.