Hi Guilhem,

On Thu, Jul 16, 2026 at 08:42:02PM +0200, Salvatore Bonaccorso wrote:
> Hi Guilhem,
> 
> On Wed, Jul 15, 2026 at 01:37:29AM +0200, Guilhem Moulin wrote:
> > Hi,
> > 
> > On Sun, 05 Jul 2026 at 17:04:05 +0200, Guilhem Moulin wrote:
> > > 1. Infinite loop in TNEF (winmail.dat) decoder
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89
> > 
> > CVE-2026-62642 was assigned for this issue.
> > 
> > > 2. Various vulnerabilities in the password plugin using
> > >  session-injected username
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c
> > 
> > CVE-2026-62644 was assigned for this issue.
> > 
> > > 3. CVE-2026-54432: Stored XSS via unescaped attachment MIME type on
> > >  the attachment-validation warning page
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/a3a4482cc9bd5569107e4393d32abb157cb2a568
> > > 4. SSRF bypass via specific local address URLs
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786
> > 
> > CVE-2026-62643 was assigned for this issue.
> > 
> > > 5. CVE-2026-54433: Zero-click stored XSS in plain-text rendering
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/63e42e233c6e8b5100e2e61a4d13addcd1a45bd5
> > > 6. DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file
> > >  
> > > https://github.com/roundcube/roundcubemail/commit/bf253c72d4293c93fda511b8464fe9cb34b522c1
> > 
> > CVE-2026-62641 was assigned for this issue.
> > 
> > As for the previous uploads, I suggest to follow 1.6.x (upstream's
> > current LTS release) for trixie-security.  Tested debdiff attached.  The
> > upstream diff [0] is pretty targeted already, although the 2 Enigma
> > changes are not security security related and arguably don't belong to
> > Debian stable.  If you prefer I can prepare another debdiff with only
> > the targeted changes linked above.
> > 
> > The proposed upload also includes a fix to restore with PHP <8
> > (unsupported since bookworm, the change is trivial enough to be worth
> > doing), see #1138086.
> 
> Please go ahead with the upload of the tested variant rebasing to the
> new upstream version.

The upload arrived, I will try to release the DSA this afternoon or
tonight.

Regards,
Salvatore

Reply via email to