CVE-2015-2181

NameCVE-2015-2181
DescriptionMultiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)buster1.3.17+dfsg.1-1~deb10u2fixed
buster (security)1.3.17+dfsg.1-1~deb10u5fixed
bullseye (security), bullseye1.4.15+dfsg.1-1~deb11u2fixed
bookworm, bookworm (security)1.6.5+dfsg-1~deb12u1fixed
trixie, sid1.6.6+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcewheezy(not affected)
roundcubesource(unstable)1.1.1+dfsg.1-2

Notes

[wheezy] - roundcube <not-affected> (variable and chgdbmailusers.c does not exist)
http://trac.roundcube.net/ticket/1490261
http://advisories.mageia.org/MGASA-2015-0400.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00032.html

Search for package or bug name: Reporting problems