CVE-2015-2181

NameCVE-2015-2181
DescriptionMultiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)stretch (security), stretch (lts), stretch1.2.3+dfsg.1-4+deb9u10fixed
buster, buster (lts)1.3.17+dfsg.1-1~deb10u7fixed
buster (security)1.3.17+dfsg.1-1~deb10u6fixed
bullseye (security), bullseye1.4.15+dfsg.1-1+deb11u4fixed
bookworm (security), bookworm1.6.5+dfsg-1+deb12u4fixed
sid, trixie1.6.9+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcewheezy(not affected)
roundcubesource(unstable)1.1.1+dfsg.1-2

Notes

[wheezy] - roundcube <not-affected> (variable and chgdbmailusers.c does not exist)
http://trac.roundcube.net/ticket/1490261
http://advisories.mageia.org/MGASA-2015-0400.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00032.html

Search for package or bug name: Reporting problems