This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 476830 - (CVE-2008-5620) CVE-2008-5620 roundcubemail: DoS due insufficient quota image size paramaters checking (use excessive amount of memory)
CVE-2008-5620 roundcubemail: DoS due insufficient quota image size paramaters...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
http://sourceforge.net/forum/forum.ph...
reported=20081216,public=20081216,sou...
: Reopened, Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2008-12-17 07:08 EST by Jan Lieskovsky
Modified: 2008-12-30 12:27 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-12-30 12:27:06 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Upstream patch (82 bytes, text/plain)
2008-12-17 07:10 EST, Jan Lieskovsky
no flags Details
/bin/html2text.php diff part extracted from upstream patch. (1.65 KB, patch)
2008-12-17 07:16 EST, Jan Lieskovsky
no flags Details | Diff
/bin/quotaimg.php diff extracted from the upstream patch (3.31 KB, patch)
2008-12-17 07:17 EST, Jan Lieskovsky
no flags Details | Diff
Downloaded upstream patch. (7.98 KB, application/x-tar)
2008-12-17 11:40 EST, Jan Lieskovsky
no flags Details

  None (edit)
Description Jan Lieskovsky 2008-12-17 07:08:43 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-5620 to
the following vulnerability:

RoundCube Webmail (roundcubemail) before 0.2-beta allows remote
attackers to cause a denial of service (memory consumption) via
crafted size parameters that are used to create a large quota image.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5620
http://sourceforge.net/forum/forum.php?forum_id=898542

Upstream patch:
http://downloads.sourceforge.net/roundcubemail/roundcubemail-0.2-beta-patch.tar.gz
Comment 1 Jan Lieskovsky 2008-12-17 07:10:34 EST
Created attachment 327236 [details]
Upstream patch
Comment 2 Jan Lieskovsky 2008-12-17 07:11:29 EST
This issue affects all versions of the Roundcubemail package, as shipped
with Fedora releases of 9, 10 and devel.
Comment 3 Jan Lieskovsky 2008-12-17 07:16:30 EST
Created attachment 327238 [details]
/bin/html2text.php diff part extracted from upstream patch.
Comment 4 Jan Lieskovsky 2008-12-17 07:17:55 EST
Created attachment 327240 [details]
/bin/quotaimg.php diff extracted from the upstream patch
Comment 6 Jan Lieskovsky 2008-12-17 11:40:56 EST
Created attachment 327267 [details]
Downloaded upstream patch.
Comment 7 Gwyn Ciesla 2008-12-17 11:42:44 EST
These patches are reflected in the current version, 0.2-beta.  This
vulnerability affects per 0.2-beta releases.
Comment 8 Tomas Hoger 2008-12-17 12:00:53 EST
Patch in comment #4 does not seem to be, or do I miss anything?
Comment 9 Gwyn Ciesla 2008-12-17 12:19:19 EST
Whoops, bad patch.  Fixing. . .
Comment 10 Fedora Update System 2008-12-17 16:10:24 EST
roundcubemail-0.2-5.beta.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/roundcubemail-0.2-5.beta.fc9
Comment 11 Fedora Update System 2008-12-17 16:10:27 EST
roundcubemail-0.2-5.beta.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/roundcubemail-0.2-5.beta.fc8
Comment 12 Fedora Update System 2008-12-17 16:10:30 EST
roundcubemail-0.2-5.beta.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/roundcubemail-0.2-5.beta.fc10
Comment 13 Fedora Update System 2008-12-21 03:28:56 EST
roundcubemail-0.2-5.beta.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 14 Fedora Update System 2008-12-21 03:31:34 EST
roundcubemail-0.2-5.beta.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 15 Fedora Update System 2008-12-21 03:34:55 EST
roundcubemail-0.2-5.beta.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.