Command injection in Roundcube Webmail - CVE-2018-9846

 

Command injection in Roundcube Webmail - CVE-2018-9846

Published: April 19, 2018 / Updated: April 22, 2018


Vulnerability identifier: #VU12078
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: CVE-2018-9846
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary IMAP command.

The vulnerability exists in Roundcube when processing user-supplied data passed via the "_uid" HTTP GET parameter to archive.php script. A remote authenticated attacker can execute arbitrary IMAP command after "%0d%0a" characters.

Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to email messages of other users.

Affected software

Roundcube Webmail
Debian Linux
Arch Linux
Fedora
roundcubemail (Alpine package)
roundcubemail

How to mitigate CVE-2018-9846

Update to version 1.1.11, 1.2.8 or 1.3.6.

roundcubemail (Alpine package) - update to 1.3.6-r0
roundcubemail - addressed in versions 1.1.11-1.el7, 1.1.12-2.el7, 1.3.6-1.fc26, 1.3.6-1.fc27, 1.3.6-1.fc28

External References

Related Security Bulletins