Candidate: CVE-2016-9920 PublicDate: 2016-12-08 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9920 https://blog.ripstech.com/2016/roundcube-command-execution-via-email/ http://www.openwall.com/lists/oss-security/2016/12/08/10 https://roundcube.net/news/2016/11/28/updates-1.2.3-and-1.1.7-released Description: steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=847287 Priority: medium Discovered-by: Robin Peraglie Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_roundcube: other: https://github.com/roundcube/roundcubemail/commit/f84233785ddeed01445fc855f3ae1e8a62f167e1 upstream_roundcube: released (1.2.3+dfsg.1-1) precise_roundcube: not-affected precise/esm_roundcube: DNE (precise was not-affected) trusty_roundcube: not-affected trusty/esm_roundcube: DNE (trusty was not-affected) vivid/stable-phone-overlay_roundcube: DNE vivid/ubuntu-core_roundcube: DNE xenial_roundcube: ignored (end of standard support, was needed) yakkety_roundcube: ignored (reached end-of-life) zesty_roundcube: not-affected (1.2.3+dfsg.1-1) artful_roundcube: not-affected (1.2.3+dfsg.1-1) bionic_roundcube: not-affected (1.3.6+dfsg.1-1) cosmic_roundcube: not-affected (1.3.6+dfsg.1-1) disco_roundcube: not-affected (1.3.6+dfsg.1-1) eoan_roundcube: not-affected (1.3.6+dfsg.1-1) focal_roundcube: not-affected (1.3.6+dfsg.1-1) groovy_roundcube: not-affected (1.3.6+dfsg.1-1) hirsute_roundcube: not-affected (1.3.6+dfsg.1-1) impish_roundcube: not-affected (1.3.6+dfsg.1-1) jammy_roundcube: not-affected (1.3.6+dfsg.1-1) devel_roundcube: not-affected (1.3.6+dfsg.1-1)