CVE-2014-9587

NameCVE-2014-9587
DescriptionMultiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-613-1
NVD severitymedium
Debian Bugs775576

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)stretch (security), stretch1.2.3+dfsg.1-4+deb9u3fixed
bullseye, sid, buster1.3.8+dfsg.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesource(unstable)1.1.1+dfsg.1-2775576
roundcubesourcewheezy0.7.2-9+deb7u4DLA-613-1

Notes

[squeeze] - roundcube <no-dsa> (Minor issue)
[wheezy] - roundcube <no-dsa> (Minor issue)
https://github.com/roundcube/roundcubemail/commit/376cbfd4f2dfcf455717409b70d9d056cbeb08b1

Search for package or bug name: Reporting problems