Koozali.org: home of the SME Server

roundcube zero day

Offline Jean-Philippe Pialasse

  • *
  • 2,765
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
roundcube zero day
« on: October 26, 2023, 06:38:43 AM »
if any of you had installed roundcube LTS 1.5.3 following wiki (https://wiki.koozali.org/RoundCube) , you need to update your install to 1.5.5. see

https://www.helpnetsecurity.com/2023/10/25/roundcube-webmail-zero-day-exploited-to-spy-on-government-entities-cve-2023-5631/

previous wiki info invited you to versionlock to 1.5.3 but you should remove this lock and update it to a more generik
 
Code: [Select]
yum versionlock  delete roundcubemail-1.5.3
yum versionlock  add roundcubemail-1.5.*
yum update