Candidate: CVE-2009-4077 PublicDate: 2009-11-25 22:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4077 Description: Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_roundcube: upstream_roundcube: released (0.3-1) dapper_roundcube: DNE hardy_roundcube: ignored (reached end-of-life) intrepid_roundcube: needs-triage (reached end-of-life) jaunty_roundcube: ignored (reached end-of-life) karmic_roundcube: ignored (reached end-of-life) lucid_roundcube: not-affected (0.3.1-3) maverick_roundcube: not-affected natty_roundcube: not-affected oneiric_roundcube: not-affected devel_roundcube: not-affected