|Category:||Mageia Linux Local Security Checks|
|Title:||Mageia Linux Local Check: mgasa-2015-0400|
|Summary:||Mageia Linux Local Security Checks mgasa-2015-0400|
Mageia Linux Local Security Checks mgasa-2015-0400
Multiple security issues in the DBMail driver for the password plugin, including buffer overflows (CVE-2015-2181) and the ability for a remote attacker to execute arbitrary shell commands as root (CVE-2015-2180). An authenticated user can download arbitrary files from the web server that the web server process has read access to, by uploading a vCard with a specially crafted POST (CVE-2015-5382). The roundcubemail package has been updated to version 1.0.6, fixing these issues and several other bugs, however the installer is currently known to be broken.
Update the affected packages to the latest available version.
Common Vulnerability Exposure (CVE) ID: CVE-2015-2180|
BugTraq ID: 96387
Common Vulnerability Exposure (CVE) ID: CVE-2015-2181
BugTraq ID: 96391
Common Vulnerability Exposure (CVE) ID: CVE-2015-5382
|Copyright||Copyright (C) 2015 Eero Volotinen|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.