Roundcube Releases Urgent Security Update to Fix Critical Bugs
Roundcube Webmail has released a security update addressing multiple critical vulnerabilities. The new stable release, version 1.6.14, resolves eight security flaws identified by independent security researchers.
Roundcube Webmail has released a security update addressing multiple critical vulnerabilities. The new stable release, version 1.6.14, resolves eight security flaws identified by independent security researchers.
The update fixes several high-severity issues that could allow attackers to manipulate user accounts, execute unauthorized actions, or extract sensitive information. Key vulnerabilities addressed include:
Pre-Auth Arbitrary File Write: An unsafe deserialization flaw in the Redis and Memcache session handler allowing unauthenticated arbitrary file writing. Authentication Bypass: A logic bug permitting password changes without requiring the old password. IMAP Injection and CSRF: A Cross-Site Request Forgery bypass combined with IMAP injection within the mail search function. Server-Side Request Forgery (SSRF): An SSRF and information disclosure vulnerability through stylesheet links pointing to local network hosts. Cross-Site Scripting (XSS): Malicious script execution triggered through HTML attachment previews.
The most severe vulnerability is the pre-authentication arbitrary-file-write flaw, stemming from unsafe deserialization in session handlers. This flaw requires no prior authentication, allowing potential remote exploitation for writing malicious files to the server.
Roundcube Webmail has released a security update addressing multiple critical vulnerabilities.
Several vulnerabilities targeted Roundcube’s email privacy protections, revealing methods to bypass remote image blocking. The update resolves these UI bypasses, ensuring tracking mechanisms and remote assets remain blocked until explicitly permitted by the user.
The Roundcube development team recommends immediate adoption of version 1.6.14. In addition to security patches, the update resolves a functional bug affecting PostgreSQL database connections using IPv6 addresses.
Administrators should update all active production installations of Roundcube 1.6.x. A comprehensive backup of all webmail data, configuration files, and underlying databases is recommended before proceeding with the update. Verification of installation packages using the provided SHA256 checksums is advised to ensure supply chain security.
Based on reporting by GBHackers.
