Bug 952006 - VUL-1: roundcubemail: unwanted access to file system in some configuration
Summary: VUL-1: roundcubemail: unwanted access to file system in some configuration
Status: RESOLVED FIXED
: 952007 952016 (view as bug list)
Alias: None
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P5 - None : Minor
Target Milestone: unspecified
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-26 12:27 UTC by Aeneas Jaißle
Modified: 2015-11-11 23:10 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aeneas Jaißle 2015-10-26 12:27:12 UTC
Tracker bug for roundcubemail.
Comment 1 Aeneas Jaißle 2015-10-26 12:48:11 UTC
https://build.opensuse.org/request/show/340988


This update fixes one security issue and one bug.

roundcubemail was updated to disallow unwanted access on files in the file system.
The apache2 configuration file for roundcubemail allowed access to the roundcubemail/bin folder and possibly /logs, /config and /temp, if these were not symlinks (this is only the case when manually changed).

This update comes with a fixed configuration. If you modified the file "/etc/apache2/conf.d/roundcubemail.conf", please replace it with the configuration "roundcubemail.conf.rpmnew" and reapply your changes. After that, a restart of apache2 is requried.

This update also fixes an issue that causes apache2 not to start because "mod_version.c" is not loaded.
Comment 3 Andreas Stieger 2015-10-26 13:20:44 UTC
*** Bug 952016 has been marked as a duplicate of this bug. ***
Comment 4 Andreas Stieger 2015-10-26 13:21:01 UTC
*** Bug 952007 has been marked as a duplicate of this bug. ***
Comment 5 Andreas Stieger 2015-10-26 13:39:22 UTC
(In reply to Aeneas Jaißle from bug 952007 comment #3)
> Btw it's all packaging updates, the upstream roundcubemail source has *not*
> changed.

I see. I understand that this makes the bug specific to openSUSE packagng.

So the issue was that if the default deployment if roundcubemail was changed in such a way that roundcubemail/bin (/logs,/config,/temp} were no longer symlinks, the configuration would allow unwanted access to these paths.

Can you confirm that this is the diff that fixes it?
https://build.opensuse.org/package/rdiff/server:php:applications/roundcubemail?linkrev=base&rev=95
Comment 6 Aeneas Jaißle 2015-10-26 13:52:33 UTC
(In reply to Andreas Stieger from comment #5)
> (In reply to Aeneas Jaißle from bug 952007 comment #3)
> > Btw it's all packaging updates, the upstream roundcubemail source has *not*
> > changed.
> 
> I see. I understand that this makes the bug specific to openSUSE packagng.
> 
> So the issue was that if the default deployment if roundcubemail was changed
> in such a way that roundcubemail/bin (/logs,/config,/temp} were no longer
> symlinks, the configuration would allow unwanted access to these paths.

/srv/www/roundcubemail/bin *is* accessible, /logs,/config, /temp *may* be accessible when changed from a symlink to a folder.
 
> Can you confirm that this is the diff that fixes it?
> https://build.opensuse.org/package/rdiff/server:php:applications/
> roundcubemail?linkrev=base&rev=95

Yes, this is the fix.
Comment 7 Aeneas Jaißle 2015-10-26 13:58:14 UTC
Oh, I just noticed that we still had 1.0.6 in the repos, so this is indeed an update to 1.0.7!
Comment 8 Aeneas Jaißle 2015-10-27 07:28:40 UTC
Resubmit with new patchinfo.

This is an update from 1.0.6 to 1.0.7, fixing an XSS issue (comment #2) as well as fixing the apache2 configuration (comment #5).
Comment 9 Aeneas Jaißle 2015-10-27 07:29:51 UTC
https://build.opensuse.org/request/show/341110
Comment 10 Andreas Stieger 2015-10-27 11:49:18 UTC
Thanks

(In reply to Aeneas Jaißle from comment #8)
> Resubmit with new patchinfo.

Not required for submissions, but we'll make sure to add the additional language.
Comment 11 Marcus Meissner 2015-11-03 16:28:20 UTC
i thinmk you also fixed this in the leap submission, I have added the bug there too.
Comment 12 Swamp Workflow Management 2015-11-04 16:12:06 UTC
openSUSE-SU-2015:1904-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 938840,952006
CVE References: 
Sources used:
openSUSE 13.2 (src):    roundcubemail-1.0.7-14.1
openSUSE 13.1 (src):    roundcubemail-1.0.7-2.24.1
Comment 13 Swamp Workflow Management 2015-11-10 10:11:36 UTC
openSUSE-SU-2015:1945-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 938840,952006
CVE References: 
Sources used:
openSUSE Leap 42.1 (src):    roundcubemail-1.1.3-3.1
Comment 14 Aeneas Jaißle 2015-11-11 23:10:15 UTC
Updates shipped