RoundCube Webmail Remote Mail Relay Vulnerability
BID:47247
Info
RoundCube Webmail Remote Mail Relay Vulnerability
| Bugtraq ID: | 47247 |
| Class: | Design Error |
| CVE: |
CVE-2011-1492 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2011 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Round Cube RoundCube Webmail 0.3.1 Round Cube RoundCube Webmail 0.2.2 Round Cube RoundCube Webmail 0.5 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
Round Cube RoundCube Webmail 0.5.1 |
Discussion
RoundCube Webmail Remote Mail Relay Vulnerability
RoundCube Webmail is prone to a mail relay vulnerability.
An attacker could exploit this issue to bypass certain security restrictions and send relay mails.
Versions prior to RoundCube Webmail 0.5.1 are vulnerable.
RoundCube Webmail is prone to a mail relay vulnerability.
An attacker could exploit this issue to bypass certain security restrictions and send relay mails.
Versions prior to RoundCube Webmail 0.5.1 are vulnerable.
Exploit / POC
RoundCube Webmail Remote Mail Relay Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
Solution / Fix
RoundCube Webmail Remote Mail Relay Vulnerability
Solution:
A vendor update is available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
A vendor update is available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
RoundCube Webmail Remote Mail Relay Vulnerability
References:
References:
- Changeset 4488 (RoundCube)
- RoundCube Webmail Changelog (RoundCube)
- Vendor Homepage (RoundCube Project)