Bug 876724 - Fix for CVE-2010-0464 in Roundcube 0.1.1 in EPEL5
Summary: Fix for CVE-2010-0464 in Roundcube 0.1.1 in EPEL5
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: roundcubemail
Version: el5
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: CVE-2010-0464
TreeView+ depends on / blocked
 
Reported: 2012-11-14 19:38 UTC by Nils Breunese
Modified: 2012-12-05 21:24 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2012-12-05 21:24:12 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Nils Breunese 2012-11-14 19:38:08 UTC
EPEL5 currently distributes roundcubemail-0.1.1-6. According to the RPM changelog several CVE security vulnerabilities have been fixed, but I did not find a mention of CVE-2010-0464 being fixed: http://www.cvedetails.com/cve/CVE-2008-5620/

According to http://www.cvedetails.com/vulnerability-list/vendor_id-8905/product_id-15709/version_id-66544/Roundcube-Roundcube-Webmail-0.1.1.html Roundcube 0.1.1 is vulnerable.

Fixes for the roundcubemail package in Fedora 11 and 12 seem to have gone out though: https://bugzilla.redhat.com/show_bug.cgi?id=560142

Comment 1 Gwyn Ciesla 2012-11-15 13:52:59 UTC
I'll look into upgrading to a higher version using the php53 stack.

Comment 2 Gwyn Ciesla 2012-11-15 20:00:09 UTC
This seems not to be immediately feasible, a patch might be faster.  Do you know if a patch for this against 0.1.1 exists?

Comment 3 Nils Breunese 2012-11-17 17:42:13 UTC
I don't know if a patch against 0.1.1 exists.

Comment 4 Gwyn Ciesla 2012-11-19 18:32:10 UTC
Found one, working on it.

Comment 5 Fedora Update System 2012-11-19 18:39:54 UTC
roundcubemail-0.1.1-7.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/roundcubemail-0.1.1-7.el5

Comment 6 Fedora Update System 2012-11-20 19:38:14 UTC
Package roundcubemail-0.1.1-7.el5:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing roundcubemail-0.1.1-7.el5'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2012-13519/roundcubemail-0.1.1-7.el5
then log in and leave karma (feedback).

Comment 7 Fedora Update System 2012-12-05 21:24:15 UTC
roundcubemail-0.1.1-7.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.