CVE Vulnerabilities

CVE-2011-4078

Published: Nov 03, 2011 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

Affected Software

Name Vendor Start Version End Version
Webmail Roundcube * 0.5.4
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1 0.1
Webmail Roundcube 0.1.1 0.1.1
Webmail Roundcube 0.2 0.2
Webmail Roundcube 0.2 0.2
Webmail Roundcube 0.2 0.2
Webmail Roundcube 0.2.1 0.2.1
Webmail Roundcube 0.3 0.3
Webmail Roundcube 0.3 0.3
Webmail Roundcube 0.3 0.3
Webmail Roundcube 0.3.1 0.3.1
Webmail Roundcube 0.4 0.4
Webmail Roundcube 0.4 0.4
Webmail Roundcube 0.4.1 0.4.1
Webmail Roundcube 0.4.2 0.4.2
Webmail Roundcube 0.5 0.5
Webmail Roundcube 0.5 0.5
Webmail Roundcube 0.5 0.5
Webmail Roundcube 0.5.1 0.5.1
Webmail Roundcube 0.5.2 0.5.2
Webmail Roundcube 0.5.3 0.5.3

References