Mageia 2020-0339: roundcubemail security update
Summary
Fix potential XSS issue in HTML editor of the identity signature input
Fix cross-site scripting (XSS) via HTML messages with malicious svg content [CVE-2020-16145]
Fix cross-site scripting (XSS) via HTML messages with malicious math content
References
- https://bugs.mageia.org/show_bug.cgi?id=27079
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.15
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16145
Resolution
MGASA-2020-0339 - Updated roundcubemail packages fix security vulnerabilities
SRPMS
- 7/core/roundcubemail-1.3.15-1.mga7