UbuntuUpdates.org

Package "roundcube-sqlite3"

Name: roundcube-sqlite3

Description:

metapackage providing SQLite dependencies for RoundCube

Latest version: 1.6.8+dfsg-2ubuntu0.1
Release: oracular (24.10)
Level: updates
Repository: universe
Head package: roundcube
Homepage: https://www.roundcube.net/

Links


Download "roundcube-sqlite3"


Other versions of "roundcube-sqlite3" in Oracular

Repository Area Version
base universe 1.6.8+dfsg-2
security universe 1.6.8+dfsg-2ubuntu0.1

Changelog

Version: 1.6.8+dfsg-2ubuntu0.1 2025-06-20 00:07:28 UTC

  roundcube (1.6.8+dfsg-2ubuntu0.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Remote code execution post authentication
    - debian/patches/CVE-2025-49113.patch: Updated
      program/actions/settings/upload.php,
      program/lib/Roundcube/rcube_utils.php and
      tests/Framework/Utils.php to validate URL parameter in upload code
    - CVE-2025-49113

 -- Chrisa Oikonomou <email address hidden> Wed, 04 Jun 2025 15:41:15 +0300

CVE-2025-49113 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n



About   -   Send Feedback to @ubuntu_updates