Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Mail Server
  • Search

Roundcube Security Vulnerability prior v1.2.3

Questions regarding the Mail Server
Dovecot, Exim, RoundCube
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
canoodle
Posts: 48
Joined: Thu Nov 27, 2014 9:34 am

Roundcube Security Vulnerability prior v1.2.3
  • Quote

Post by canoodle » Thu Dec 08, 2016 5:44 pm

is this an issue? and is it fixed? :-D

if not: how can i disable / uninstall coundcube i am not using it... thanks!

https://github.com/roundcube/roundcube ... elease-123

heise Security
08.12.2016 17:58 Uhr

https://www.heise.de/newsticker/meldung ... itrag.atom
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Roundcube Security Vulnerability prior v1.2.3
  • Quote

Post by ScIT » Thu Dec 08, 2016 7:17 pm

To use this security breach you will need to have a local email account - so it is not a big problem like it is written on heise.de. As soon, as the new package is published (roundcube-core), you can install it over system upgrade (apt-get upgrade / yum update).

VestaCP does not provide an own roundcube version, if you want to disable roundcube, you can to this for example by removing the /webmail alias from the system:

Code: Select all

rm /etc/apache2/conf.d/roundcube.conf
service apache2 restart
if you want to re-enable it, you can create again the symlink:

Code: Select all

ln -s /etc/roundcube/apache.conf /etc/apache2/conf.d/roundcube.conf
service apache2 restart
This will work for Ubuntu and Debian, should be a similar way for CentOS/Redhat systems.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Roundcube Security Vulnerability prior v1.2.3
  • Quote

Post by ScIT » Fri Dec 09, 2016 8:47 am

There seems to be no security issue with exim4 and VestaCP, the needed switches (-X and -O) will be ignored from exim4 sendmail. Source: https://www.heise.de/forum/heise-Securi ... 5767/show/
Top

canoodle
Posts: 48
Joined: Thu Nov 27, 2014 9:34 am

Re: Roundcube Security Vulnerability prior v1.2.3
  • Quote

Post by canoodle » Fri Dec 09, 2016 1:35 pm

Thank you for your fast and competent answers :)

(Y) *thumbs*up*
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “Mail Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password