VDB

CVE-2018-1000071

CVE-2018-1000071 PUBLISHED CVSS 7.5 HIGH

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

EPSS 1.68% · 76.1th percentile

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.68%
76.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSroundcube0, 1.3.0+dfsg.1-1, 1.3.1+dfsg.1-1
Ubuntu:Pro:16.04:LTSroundcube0, 1.1.1+dfsg.1-2, 1.1.2+dfsg.1-5

Timeline

  • Mar 13, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Mar 2, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 13, 2023 EPSS Score
  • Mar 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›