Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0464 to the following vulnerability: Name: CVE-2010-0464 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0464 Assigned: 20100129 Reference: MISC: https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail Reference: CONFIRM: http://trac.roundcube.net/ticket/1486449 Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.
roundcubemail-0.3.1-2.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
roundcubemail-0.3.1-2.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.