Name | CVE-2013-5645 |
Description | Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 721592 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
roundcube (PTS) | stretch (security), stretch (lts), stretch | 1.2.3+dfsg.1-4+deb9u10 | fixed |
buster, buster (lts) | 1.3.17+dfsg.1-1~deb10u7 | fixed | |
buster (security) | 1.3.17+dfsg.1-1~deb10u6 | fixed | |
bullseye (security), bullseye | 1.4.15+dfsg.1-1+deb11u4 | fixed | |
bookworm (security), bookworm | 1.6.5+dfsg-1+deb12u4 | fixed | |
sid, trixie | 1.6.9+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
roundcube | source | (unstable) | 0.9.4-1 | 721592 |
[wheezy] - roundcube <no-dsa> (Minor issue)
[squeeze] - roundcube <no-dsa> (Minor issue)
http://web.archive.org/web/20160311164159/http://trac.roundcube.net/changeset/93b0a30c1c8aa29d862b587b31e52bcc344b8d16/github
http://web.archive.org/web/20160311132902/http://trac.roundcube.net/changeset/ce5a6496fd6039962ba7424d153278e41ae8761b/github
http://trac.roundcube.net/ticket/1489251