Candidate: CVE-2019-15237 PublicDate: 2019-08-20 01:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15237 https://github.com/roundcube/roundcubemail/issues/6891 Description: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N [7.4 HIGH] Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/b913d2fbdef8c351273ee12e307405e04eb0d550 upstream_roundcube: released (1.5.0) precise/esm_roundcube: DNE trusty_roundcube: ignored (out of standard support) trusty/esm_roundcube: DNE (trusty was needed) xenial_roundcube: ignored (end of standard support, was needed) bionic_roundcube: needed disco_roundcube: ignored (reached end-of-life) eoan_roundcube: ignored (reached end-of-life) focal_roundcube: needed groovy_roundcube: ignored (reached end-of-life) hirsute_roundcube: ignored (reached end-of-life) impish_roundcube: needed jammy_roundcube: released (1.5.0+dfsg.1-2) devel_roundcube: released (1.5.0+dfsg.1-2)