Er zijn updates verschenen voor versies 1.6 en 1.7 van Roundcube Webmail die diverse beveiligensproblemen moeten verhelpen. Roundcube Webmail biedt een webinterface om e-mail te kunnen lezen en verzenden. Het heeft onder andere ondersteuning voor gedeelde mappen en namespaces, internationalized domain names en SMTP-afleverstatusnotificaties. Daarnaast is de gebruikersinterface voor IMAP-mappen aangepast om zo meer ruimte te bieden voor extensies en plug-ins. De changelog voor beide versies kan hieronder worden gevonden.
Security updates 1.6.18 and 1.7.3 releasedWe just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.
Security fixes
- Add basic validation for content proxied by the css proxy
- Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the
search_filter- Fix arbitrary Sieve script injection via a filter rule name bypassing
managesieve_disabled_actions- Fix RCE via cmd_learn driver of markasjunk plugin
- Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Fix password’s modoboa driver leak of an authentication token to a user-controlled host
- Fix stored XSS in “Add to address book” action
- Fix HTML/CSS sanitization bypass via SVG animate
byattributeSee the full changelogs in the release notes on the Github download pages for the updated versions 1.6.18 and 1.7.3. We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.

/u/176086/crop5f0823fa5e8d6_cropped.png?f=community)
:strip_exif()/u/26559/SunDrop_60_got.gif?f=community)