Ubuntu Security Update USN-8097-2: roundcube regression

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,739
Reaction score
74
Credits
-1,257
USN-8097-1 fixed a vulnerability in roundcube. The update caused a regression affecting the HTML sanitizer, preventing Roundcube from rendering any email message body. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack.

Continue reading...
 


Follow Linux.org

Members online


Top