CVE-2015-1433
Publication date 3 February 2015
Last updated 24 July 2024
Ubuntu priority
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
Status
Package | Ubuntu Release | Status |
---|---|---|
roundcube | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
References
Other references
- http://www.openwall.com/lists/oss-security/2015/01/31/6
- http://www.openwall.com/lists/oss-security/2015/01/31/3
- http://trac.roundcube.net/ticket/1490227
- http://trac.roundcube.net/changeset/786aa0725/github
- http://roundcube.net/news/2015/01/24/security-update-1.0.5/
- https://www.cve.org/CVERecord?id=CVE-2015-1433