Hi Guilhem,

On Wed, Jul 15, 2026 at 01:37:29AM +0200, Guilhem Moulin wrote:
> Hi,
> 
> On Sun, 05 Jul 2026 at 17:04:05 +0200, Guilhem Moulin wrote:
> > 1. Infinite loop in TNEF (winmail.dat) decoder
> >  
> > https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38
> >  
> > https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89
> 
> CVE-2026-62642 was assigned for this issue.
> 
> > 2. Various vulnerabilities in the password plugin using
> >  session-injected username
> >  
> > https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476
> >  
> > https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c
> 
> CVE-2026-62644 was assigned for this issue.
> 
> > 3. CVE-2026-54432: Stored XSS via unescaped attachment MIME type on
> >  the attachment-validation warning page
> >  
> > https://github.com/roundcube/roundcubemail/commit/a3a4482cc9bd5569107e4393d32abb157cb2a568
> > 4. SSRF bypass via specific local address URLs
> >  
> > https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786
> 
> CVE-2026-62643 was assigned for this issue.
> 
> > 5. CVE-2026-54433: Zero-click stored XSS in plain-text rendering
> >  
> > https://github.com/roundcube/roundcubemail/commit/63e42e233c6e8b5100e2e61a4d13addcd1a45bd5
> > 6. DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file
> >  
> > https://github.com/roundcube/roundcubemail/commit/bf253c72d4293c93fda511b8464fe9cb34b522c1
> 
> CVE-2026-62641 was assigned for this issue.
> 
> As for the previous uploads, I suggest to follow 1.6.x (upstream's
> current LTS release) for trixie-security.  Tested debdiff attached.  The
> upstream diff [0] is pretty targeted already, although the 2 Enigma
> changes are not security security related and arguably don't belong to
> Debian stable.  If you prefer I can prepare another debdiff with only
> the targeted changes linked above.
> 
> The proposed upload also includes a fix to restore with PHP <8
> (unsupported since bookworm, the change is trivial enough to be worth
> doing), see #1138086.

Please go ahead with the upload of the tested variant rebasing to the
new upstream version.

Regards,
Salvatore

Reply via email to