Security restrictions bypass in Roundcube Webmail - CVE-2017-8114
Published: July 12, 2017
Vulnerability identifier: #VU7478
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8114
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The weakness exists due to improper restriction of exec call in the virtualmin and sasl drivers of the password plugin. A remote attcker can arbitrarily reset passwords, bypass security restrictions and gain elevated privileges on the system.
Successful exploitation of the vulnerability results in privilege escalation.
The weakness exists due to improper restriction of exec call in the virtualmin and sasl drivers of the password plugin. A remote attcker can arbitrarily reset passwords, bypass security restrictions and gain elevated privileges on the system.
Successful exploitation of the vulnerability results in privilege escalation.
Affected software
Roundcube Webmail
roundcubemail (Alpine package)
roundcubemail
Fedora
roundcubemail (Alpine package)
roundcubemail
Fedora
How to mitigate CVE-2017-8114
Update to version 1.0.11, 1.1.9 or 1.2.5.
roundcubemail (Alpine package) - update to 1.1.9-r0
roundcubemail - addressed in versions 1.1.9-1.el7, 1.2.5-1.fc24, 1.2.5-1.fc25, 1.2.5-1.fc26
roundcubemail - addressed in versions 1.1.9-1.el7, 1.2.5-1.fc24, 1.2.5-1.fc25, 1.2.5-1.fc26