Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Debian Security

DSA-6479-1 roundcube - security update

  • What: Security update for Roundcube mail application
  • Impact: Debian users running affected versions may be vulnerable to multiple security issues
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6479-1] roundcube security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6479-1] roundcube security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Sun, 30 Aug 2026 19:15:22 +0000 Message-id: <[🔎] E1x0kzy-0000000BgZV-06Q7@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6479-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 30, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : roundcube CVE ID : CVE-2026-74997 CVE-2026-74998 CVE-2026-74999 CVE-2026-75000 CVE-2026-75002 CVE-2026-75003 CVE-2026-75004 CVE-2026-75006 CVE-2026-75007 CVE-2026-75010 Debian Bug : 1144059 Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in cross-site scripting, SSRF bypass, information disclosure, privilege escalation, denial of service or remote code execution. For the stable distribution (trixie), these problems have been fixed in version 1.6.18+dfsg-0+deb13u1. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/roundcube Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqUgRhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QlIA/+I6kzvzeCB08BomMJgV9cUWVsaMAeY7U4o3lH9x14NO6v+0iIARStIi+Q 3cyFq5O7MHCfe05zR+sW34b7m5ZqLIw9hUnSrMeaKoRuO1gJ/nWyInsujz8MvzP6 kv8nDXh2VycTfdlnVy+y+HW7LN7jXFuIth272ZJpQStTikZB7/1b+jhlpa3WXqF6 FzVJrt5IXC8DiJ+WRSY1NbAHzn8/pj4KC4jwODFa5+iffBV8PxBdI+oomFLjGKtM DV6RyBAk6VaNBoJl/87IlUw2Hc4BXi7FlQBvn3+6mZ5LUsWGc26/GBqvvcLFN3Au 7yVOJLrS/h3LRQOFQ3QfRnRA9im5TGXGYSu5xpCnYnuB50E7ZrBt3ZAXsoYNp2bX J/i5YBHvdpeh4VmaVJ1Va9l+45siqbYM/fzQCYZ7gK7JTfTvh1rXstQSZgt8Z+X6 I3zaoLtzuop7LjkfgfN3eVTbznoYQrhAX00RcELUIDuJs1pYF9ddy+ul/GiomzIq 07Hv48XUDQcukVe2ZRwg2YJrhCbsZxK/XEkk6TP5r3GyzKemcMu6+W0bRmOpQ8zv nIlCn3OkX23+vTtJ3Y/EviWoQXHd2Dd55UKFq8m2cf6gsdbF4/x3yUccBCZ7juc1 V1nQkof2ImLmkJ3h7BVr68wg58jR3TG00s9K2uQaLI58YYGhd2w= =BIuq -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6478-1] starlette security update Previous by thread: [SECURITY] [DSA 6478-1] starlette security update Index(es): Date Thread

Share this article