Candidate: CVE-2018-19205 PublicDate: 2018-11-12 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19205 https://roundcube.net/news/2018/07/27/update-1.3.7-released https://github.com/roundcube/roundcubemail/issues/6289 https://github.com/roundcube/roundcubemail/commit/94da947855329c5062ec2a7098eb86fb675aac37 (release-1.3) https://github.com/roundcube/roundcubemail/commit/2fa112bd836e5e144e270bda11c9fda1a66a22ae (master) https://github.com/roundcube/roundcubemail/releases/tag/1.3.7 Description: Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/94da947855329c5062ec2a7098eb86fb675aac37 upstream_roundcube: released (1.3.7) precise/esm_roundcube: DNE trusty_roundcube: ignored (reached end-of-life) trusty/esm_roundcube: DNE (trusty was not-affected) xenial_roundcube: ignored (end of standard support, was needed) bionic_roundcube: needed cosmic_roundcube: ignored (reached end-of-life) disco_roundcube: not-affected (1.3.8+dfsg.1-2) eoan_roundcube: not-affected (1.3.8+dfsg.1-2) focal_roundcube: not-affected (1.4.3+dfsg.1-1) groovy_roundcube: not-affected (1.4.3+dfsg.1-1) hirsute_roundcube: not-affected (1.4.3+dfsg.1-1) impish_roundcube: not-affected (1.4.11+dfsg.1-4) jammy_roundcube: not-affected (1.5.0+dfsg.1-2) devel_roundcube: not-affected (1.5.0+dfsg.1-2)