CVE-2020-12641
04.05.2020, 15:15
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
| Vendor | Product | Version |
|---|---|---|
| roundcube | webmail | 1.2.0 ≤ 𝑥 < 1.2.10 |
| roundcube | webmail | 1.3.0 ≤ 𝑥 < 1.3.11 |
| roundcube | webmail | 1.4.0 ≤ 𝑥 < 1.4.4 |
| opensuse | backports_sle | 15.0:sp1 |
| opensuse | backports_sle | 15.0:sp2 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| roundcube |
|
References