TEMP-1131182-79F7AC

NameTEMP-1131182-79F7AC
DescriptionIMAP Injection + CSRF bypass in mail search
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1131182

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u7vulnerable
bookworm1.6.5+dfsg-1+deb12u6vulnerable
bookworm (security)1.6.5+dfsg-1+deb12u7vulnerable
trixie (security), trixie1.6.13+dfsg-0+deb13u1vulnerable
forky, sid1.6.13+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesource(unstable)(unfixed)1131182

Notes

https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.16
Fixed by: https://github.com/roundcube/roundcubemail/commit/5fe8a69956a9683a4269f3ad2a68e18deebf8a15

Search for package or bug name: Reporting problems