Buffer overflow in Roundcube Webmail - CVE-2015-2181

 

Buffer overflow in Roundcube Webmail - CVE-2015-2181

Published: January 31, 2017 / Updated: August 3, 2020


Vulnerability identifier: #VU33075
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2181
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.


Affected software

Roundcube Webmail
roundcubemail (Alpine package)

How to mitigate CVE-2015-2181

Install update from vendor's website.

Roundcube Webmail - update to 1.1.0
roundcubemail (Alpine package) - update to 1.0.9-r0

External References

Related Security Bulletins