Bug ID 982003
Summary VUL-0: CVE-2016-5103: roundcube: XSS vulnerability in mail content page
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.1
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee nix@opensuse.org
Reporter abergmann@suse.com
QA Contact qa-bugs@suse.de
CC aj@ajaissle.de, lrupp@suse.com, wolfgang@rosenauer.org
Found By Security Response Team
Blocker ---

rh#1339654

A 1.2.0 release of roundcubemail fixed an XSS vulnerability in href attribute
on area tag.

External references:

https://github.com/roundcube/roundcubemail/issues/5240

Upstream fix:

https://github.com/roundcube/roundcubemail/pull/5241

CVE assignment:

http://seclists.org/oss-sec/2016/q2/414

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1339654
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5103
http://seclists.org/oss-sec/2016/q2/414


You are receiving this mail because: