Improper Neutralization of Argument Delimiters in a Command in Roundcube Webmail - CVE-2020-12641

 

Improper Neutralization of Argument Delimiters in a Command in Roundcube Webmail - CVE-2020-12641

Published: June 11, 2020 / Updated: June 20, 2023


Vulnerability identifier: #VU28980
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12641
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in rcube_image.php script when processing shell metacharacters in a configuration setting for im_convert_path or im_identify_path. A remote user with ability to change Roundcube Webmail configuration can inject and execute arbitrary OS commands.


Affected software

Roundcube Webmail
Gentoo Linux
SUSE Linux
Opensuse
Fedora
roundcubemail

How to mitigate CVE-2020-12641

Install update from vendor's website.

Roundcube Webmail - addressed in versions 1.2.10, 1.3.11, 1.4.4
roundcubemail - addressed in versions 1.4.5-1.fc31, 1.4.5-1.fc32, 1.4.6-1.fc31, 1.4.6-1.fc32

External References

Related Security Bulletins