Candidate: CVE-2010-0464 PublicDate: 2010-01-29 18:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0464 Description: Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. Ubuntu-Description: Notes: Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_roundcube: upstream_roundcube: released (0.3.1-3) dapper_roundcube: DNE hardy_roundcube: ignored (reached end-of-life) intrepid_roundcube: needs-triage (reached end-of-life) jaunty_roundcube: ignored (reached end-of-life) karmic_roundcube: ignored (reached end-of-life) lucid_roundcube: not-affected (0.3.1-3) maverick_roundcube: not-affected natty_roundcube: not-affected oneiric_roundcube: not-affected devel_roundcube: not-affected