CVE-2013-1904
Publication date 8 February 2014
Last updated 24 July 2024
Ubuntu priority
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
Status
Package | Ubuntu Release | Status |
---|---|---|
roundcube | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |