TEMP-1122899-F63EED

NameTEMP-1122899-F63EED
DescriptionCross-Site-Scripting vulnerability via SVG's animate tag
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1122899

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u5vulnerable
bookworm, bookworm (security)1.6.5+dfsg-1+deb12u5vulnerable
forky, trixie1.6.11+dfsg-1vulnerable
sid1.6.12+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesource(unstable)1.6.12+dfsg-11122899

Notes

https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12
Fixed by: https://github.com/roundcube/roundcubemail/commit/bfa032631c36b900e7444dfa278340b33cbf7cdb (1.6.12)

Search for package or bug name: Reporting problems