{"id":"openSUSE-SU-2020:1516-1","summary":"Security update for roundcubemail","details":"This update for roundcubemail fixes the following issues:\n\nroundcubemail was upgraded to 1.3.15\n\nThis is a security update to the LTS version 1.3. (boo#1175135)\n\n  * Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]\n  * Security: Fix cross-site scripting (XSS) via HTML messages with malicious math content\n\nFrom 1.3.14 (boo#1173792 -\u003e CVE-2020-15562)\n\n  * Security: Fix cross-site scripting (XSS) via HTML messages with malicious svg/namespace\n\nFrom 1.3.13\n\n  * Installer: Fix regression in SMTP test section (#7417)\n\nFrom 1.3.12\n\n  * Security: Better fix for CVE-2020-12641 (boo#1171148)\n  * Security: Fix XSS issue in template object 'username' (#7406)\n  * Security: Fix couple of XSS issues in Installer (#7406)\n  * Security: Fix cross-site scripting (XSS) via malicious XML attachment\n\nFrom 1.3.11 (boo#1171148 -\u003e CVE-2020-12641 boo#1171040 -\u003e CVE-2020-12625 boo#1171149 -\u003e CVE-2020-12640)\n\n  * Enigma: Fix compatibility with Mail_Mime \u003e= 1.10.5\n  * Fix permissions on some folders created by bin/install-jsdeps.sh script (#6930)\n  * Fix bug where inline images could have been ignored if Content-Id header contained redundant spaces (#6980)\n  * Fix PHP Warning: Use of undefined constant LOG_EMERGE (#6991)\n  * Fix PHP warning: 'array_merge(): Expected parameter 2 to be an array, null given in sendmail.inc (#7003)\n  * Security: Fix XSS issue in handling of CDATA in HTML messages\n  * Security: Fix remote code execution via crafted 'im_convert_path' or 'im_identify_path' settings\n  * Security: Fix local file inclusion (and code execution) via crafted 'plugins' option\n  * Security: Fix CSRF bypass that could be used to log out an authenticated user (#7302)\n\nFrom 1.3.10 (boo#1146286)\n\n  * Managesieve: Fix so 'Create filter' option does not show up when Filters menu is disabled (#6723)\n  * Enigma: Fix bug where revoked users/keys were not greyed out in key info\n  * Enigma: Fix error message when trying to encrypt with a revoked key (#6607)\n  * Enigma: Fix 'decryption oracle' bug [CVE-2019-10740] (#6638) \n  * Fix compatibility with kolab/net_ldap3 \u003e 1.0.7 (#6785)\n  * Fix bug where bmp images couldn't be displayed on some systems (#6728)\n  * Fix bug in parsing vCard data using PHP 7.3 due to an invalid regexp (#6744)\n  * Fix bug where bold/strong text was converted to upper-case on html-to-text conversion (6758)\n  * Fix bug in rcube_utils::parse_hosts() where %t, %d, %z could return only tld (#6746)\n  * Fix bug where Next/Prev button in mail view didn't work with multi-folder search result (#6793)\n  * Fix bug where selection of columns on messages list wasn't working\n  * Fix bug in converting multi-page Tiff images to Jpeg (#6824)\n  * Fix wrong messages order after returning to a multi-folder search result (#6836)\n  * Fix PHP 7.4 deprecation: implode() wrong parameter order (#6866)\n  * Fix bug where it was possible to bypass the position:fixed CSS check in received messages (#6898)\n  * Fix bug where some strict remote URIs in url() style were unintentionally blocked (#6899)\n  * Fix bug where it was possible to bypass the CSS jail in HTML messages using :root pseudo-class (#6897)\n  * Fix bug where it was possible to bypass href URI check with data:application/xhtml+xml URIs (#6896)\n\nFrom 1.3.9 (boo#1115718)\n\n  * Fix TinyMCE download location (#6694)\n  * Fix bug where a message/rfc822 part without a filename wasn't listed on the attachments list (#6494)\n  * Fix handling of empty entries in vCard import (#6564)\n  * Fix bug in parsing some IMAP command responses that include unsolicited replies (#6577)\n  * Fix PHP 7.2 compatibility in debug_logger plugin (#6586)\n  * Fix so ANY record is not used for email domain validation, use A, MX, CNAME, AAAA instead (#6581)\n  * Fix so mime_content_type check in Installer uses files that should always\n    be available (i.e. from program/resources) (#6599)\n  * Fix missing CSRF token on a link to download too-big message part (#6621)\n  * Fix bug when aborting dragging with ESC key didn't stop the move action (#6623)\n  * Fix bug where next row wasn't selected after deleting a collapsed thread (#6655)\n\nFrom 1.3.8 \n\n  * Fix PHP warnings on dummy QUOTA responses in Courier-IMAP 4.17.1 (#6374)\n  * Fix so fallback from BINARY to BODY FETCH is used also on [PARSE] errors in dovecot 2.3 (#6383)\n  * Enigma: Fix deleting keys with authentication subkeys (#6381)\n  * Fix invalid regular expressions that throw warnings on PHP 7.3 (#6398)\n  * Fix so Classic skin splitter does not escape out of window (#6397)\n  * Fix XSS issue in handling invalid style tag content (#6410)\n  * Fix compatibility with MySQL 8 - error on 'system' table use\n  * Managesieve: Fix bug where show_real_foldernames setting wasn't respected (#6422)\n  * New_user_identity: Fix %fu/%u vars substitution in user specific LDAP params (#6419)\n  * Fix support for 'allow-from \u003curi\u003e' in 'x_frame_options' config option (#6449)\n  * Fix bug where valid content between HTML comments could have been skipped in some cases (#6464)\n  * Fix multiple VCard field search (#6466)\n  * Fix session issue on long running requests (#6470)\n\nFrom 1.3.7 (boo#1115719)\n\n  * Fix PHP Warning: Use of undefined constant IDNA_DEFAULT on systems without php-intl (#6244)\n  * Fix bug where some parts of quota information could have been ignored (#6280)\n  * Fix bug where some escape sequences in html styles could bypass security checks\n  * Fix bug where some forbidden characters on Cyrus-IMAP were not prevented from use in folder names\n  * Fix bug where only attachments with the same name would be ignored on zip download (#6301)\n  * Fix bug where unicode contact names could have been broken/emptied or caused DB errors (#6299)\n  * Fix bug where after 'mark all folders as read' action message counters were not reset (#6307)\n  * Enigma: [EFAIL] Don't decrypt PGP messages with no MDC protection (#6289)\n  * Fix bug where some HTML comments could have been malformed by HTML parser (#6333)\n","modified":"2026-03-11T07:32:40.981343Z","published":"2020-09-24T12:21:24Z","related":["CVE-2019-10740","CVE-2020-12625","CVE-2020-12640","CVE-2020-12641","CVE-2020-15562","CVE-2020-16145"],"upstream":["CVE-2019-10740","CVE-2020-12625","CVE-2020-12640","CVE-2020-12641","CVE-2020-15562","CVE-2020-16145"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3FA23YXQFYWKLULMWY4AOGET45U5NWC4/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171040"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173792"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-10740"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12625"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12640"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15562"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-16145"}],"affected":[{"package":{"name":"roundcubemail","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.15-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"roundcubemail":"1.3.15-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1516-1.json"}},{"package":{"name":"roundcubemail","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/roundcubemail&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.15-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"roundcubemail":"1.3.15-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1516-1.json"}},{"package":{"name":"roundcubemail","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.15-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"roundcubemail":"1.3.15-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1516-1.json"}},{"package":{"name":"roundcubemail","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.15-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"roundcubemail":"1.3.15-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:1516-1.json"}}],"schema_version":"1.7.5"}