Candidate: CVE-2012-6121 PublicDate: 2013-02-24 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6121 http://www.openwall.com/lists/oss-security/2013/02/07 http://trac.roundcube.net/ticket/1488850 http://sourceforge.net/news/?group_id=139281&id=310213 Description: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/74cd0a9b62f11bc07c5a1d3ba0098b54883eb0ba upstream_roundcube: released (0.8.5) hardy_roundcube: ignored (reached end-of-life) lucid_roundcube: ignored (reached end-of-life) oneiric_roundcube: ignored (reached end-of-life) precise_roundcube: ignored (reached end-of-life) precise/esm_roundcube: DNE (precise was needs-triage) quantal_roundcube: ignored (reached end-of-life) raring_roundcube: ignored (reached end-of-life) saucy_roundcube: not-affected (0.9.2-2) trusty_roundcube: not-affected (0.9.5-4) trusty/esm_roundcube: DNE (trusty was not-affected [0.9.5-4]) utopic_roundcube: not-affected (0.9.5-4) vivid_roundcube: not-affected (0.9.5-4) vivid/stable-phone-overlay_roundcube: DNE vivid/ubuntu-core_roundcube: DNE wily_roundcube: not-affected (0.9.5-4) xenial_roundcube: not-affected (0.9.5-4) yakkety_roundcube: not-affected (0.9.5-4) zesty_roundcube: not-affected (0.9.5-4) devel_roundcube: not-affected (0.9.5-4)