VDB
BDU%3A2023-07518
BDU%3A2023-07518
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функций im_convert_path и im_identify_path файла rcube_image.php почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., The RoundCube Team | OpenSUSE Leap, openSUSE Backports, RoundCube Webmail |
Timeline
- Nov 8, 2023 CVE Published
- Sep 24, 2024 CVE Updated
- Mar 19, 2026 Security Advisory
References
- https://roundcube.net/news/2020/04/29/security-updates-1.4.4-1.3.11-and-1.2.10 url
- https://github.com/roundcube/roundcubemail/releases/tag/1.4.4 url
- https://github.com/roundcube/roundcubemail/compare/1.4.3...1.4.4 url
- https://github.com/roundcube/roundcubemail/commit/fcfb099477f353373c34c8a65c9035b06b364db3 url
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-12641-Command%20Injection-Roundcube url
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.html url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3FA23YXQFYWKLULMWY4AOGET45U5NWC4/ advisory