PT-2016-7880 · Roundcube+2 · Roundcube+2

Robin Peraglie

·

Published

2016-11-30

·

Updated

2026-03-30

·

CVE-2016-9920

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roundcube versions prior to 1.1.7 Roundcube versions 1.2.x prior to 1.2.3
Description The issue allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message. This is due to the improper restriction of custom envelope-from addresses on the sendmail command line when no SMTP server is configured and the sendmail program is enabled.
Recommendations For Roundcube versions prior to 1.1.7, update to version 1.1.7 or later. For Roundcube versions 1.2.x prior to 1.2.3, update to version 1.2.3 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2377
CVE-2016-9920
DLA-737-1
MGASA-2016-0430
USN-8132-1

Affected Products

Alt Linux
Roundcube
Ubuntu