ELA-1170-1 roundcube security update

Multiple vulnerabilities (privilege escalation, information disclosure, DoS)

2024-08-30
Packageroundcube
Version1.3.17+dfsg.1-1~deb10u7 (buster)
Related CVEs CVE-2024-42008 CVE-2024-42009 CVE-2024-42010


Multiple cross-site scripting (XSS) vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could lead to privilege escalation, information disclosure or denial of service.



For Debian 10 buster, these problems have been fixed in version 1.3.17+dfsg.1-1~deb10u7.

We recommend that you upgrade your roundcube packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.