RoundCube Webmail Denial of Service Vulnerability
BID:50402
Info
RoundCube Webmail Denial of Service Vulnerability
| Bugtraq ID: | 50402 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-4078 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2011 12:00AM |
| Updated: | Mar 19 2015 09:32AM |
| Credit: | star26bsd |
| Vulnerable: |
Round Cube RoundCube Webmail 0.5.4 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 HP System Management Homepage 7.0 HP System Management Homepage 6.3 HP System Management Homepage 6.2 HP System Management Homepage 6.1 HP System Management Homepage 6.0 |
| Not Vulnerable: | |
Discussion
RoundCube Webmail Denial of Service Vulnerability
RoundCube Webmail is prone to a denial-of-service vulnerability because the application fails to properly handle certain emails containing a URI link in the subject.
An attacker can exploit this issue to disable the victim user's ability to access their mail INBOX, resulting in a denial-of-service condition.
RoundCube Webmail is prone to a denial-of-service vulnerability because the application fails to properly handle certain emails containing a URI link in the subject.
An attacker can exploit this issue to disable the victim user's ability to access their mail INBOX, resulting in a denial-of-service condition.
Exploit / POC
RoundCube Webmail Denial of Service Vulnerability
An attacker may trigger this issue by sending a specially crafted email message to a targeted victim.
An attacker may trigger this issue by sending a specially crafted email message to a targeted victim.
Solution / Fix
RoundCube Webmail Denial of Service Vulnerability
Solution:
A vendor update is available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
MandrakeSoft Enterprise Server 5 x86_64
Solution:
A vendor update is available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva roundcubemail-0.7.2-0.1mdvmes5.2.noarch.rpm
http://www.mandriva.com/en/downloads/
References
RoundCube Webmail Denial of Service Vulnerability
References:
References:
- RC can be DoS'ed by sending specific email (Roundcube)
- Vendor Homepage (RoundCube Project)