Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Forum for things that doesn't really have anything to do with hMailServer. Such as php.ini, beer, etc etc.
Post Reply

palinka
Senior user
Senior user
Posts: 4352
Joined: 2017-09-12 17:57

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by palinka » 2023-10-25 20:05

Is there a patch yet?

mats
Normal user
Normal user
Posts: 45
Joined: 2018-05-06 20:58

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by mats » 2023-10-25 21:16

palinka wrote:
2023-10-25 20:05
Is there a patch yet?
Yes since about 10 days ago


User avatar
RvdH
Senior user
Senior user
Posts: 3092
Joined: 2008-06-27 14:42
Location: The Netherlands

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by RvdH » 2023-11-06 10:08

https://github.com/roundcube/roundcubem ... /tag/1.6.5

Roundcube Webmail 1.6.5

Code: Select all

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides a fix to a recently reported XSS vulnerability:

Fix cross-site scripting (XSS) vulnerability in setting Content-Type/Content-Disposition for attachment preview/download reported by Rene Rehme (rehme.infosec).
This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!
For Roundcube Webmail 1.5.6 version, see:
https://github.com/roundcube/roundcubemail/releases
CIDR to RegEx: d-fault.nl/cidrtoregex
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup

danieldummer
New user
New user
Posts: 7
Joined: 2017-08-31 14:39

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by danieldummer » 2023-11-20 20:48

Anyone knows if the latest version of HMailServer ( 5.6.8 ) is compatible with the latest version of RoundCube ( 1.6.5 )?

Thanks

gotspatel
Senior user
Senior user
Posts: 341
Joined: 2013-10-08 05:42
Location: INDIA

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by gotspatel » 2023-11-21 05:33

It has nothing to do with the roundcube version with hmailserver version since roundcube is just a mail client.

you can use any roundcube version with any version of hamilserver

Regards

danieldummer
New user
New user
Posts: 7
Joined: 2017-08-31 14:39

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by danieldummer » 2023-11-21 16:28

gotspatel wrote:
2023-11-21 05:33
It has nothing to do with the roundcube version with hmailserver version since roundcube is just a mail client.

you can use any roundcube version with any version of hamilserver

Regards
Thank you

User avatar
RvdH
Senior user
Senior user
Posts: 3092
Joined: 2008-06-27 14:42
Location: The Netherlands

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by RvdH » 2023-11-29 14:40

https://nextcloud.com/blog/open-source- ... nextcloud/

Can't they pickup hMailServer development as well? :lol:
CIDR to RegEx: d-fault.nl/cidrtoregex
DNS Lookup: d-fault.nl/dnstools
DKIM Generator: d-fault.nl/dkimgenerator
DNSBL Lookup: d-fault.nl/dnsbllookup
GEOIP Lookup: d-fault.nl/geoiplookup

palinka
Senior user
Senior user
Posts: 4352
Joined: 2017-09-12 17:57

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by palinka » 2023-11-29 15:11

RvdH wrote:
2023-11-29 14:40
https://nextcloud.com/blog/open-source- ... nextcloud/

Can't they pickup hMailServer development as well? :lol:
Linux only! :lol: :lol: :lol:

User avatar
mattg
Moderator
Moderator
Posts: 22387
Joined: 2007-06-14 05:12
Location: 'The Outback' Australia

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by mattg » 2023-11-30 01:45

palinka wrote:
2023-11-29 15:11
RvdH wrote:
2023-11-29 14:40
https://nextcloud.com/blog/open-source- ... nextcloud/

Can't they pickup hMailServer development as well? :lol:
Linux only! :lol: :lol: :lol:
Don't think so.
It is written in PHP.

I'm a long term user of Nextcloud - love it.
They already have a web mail client called Snappy Mail that is an app inclusion, but exciting to see them get a hold of roundcube too.

Nextcloud is an offshoot or OwnCloud
Just 'cause I link to a page and say little else doesn't mean I am not being nice.
https://www.hmailserver.com/documentation

palinka
Senior user
Senior user
Posts: 4352
Joined: 2017-09-12 17:57

Re: Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

Post by palinka » 2023-11-30 07:55

mattg wrote:
2023-11-30 01:45
palinka wrote:
2023-11-29 15:11
RvdH wrote:
2023-11-29 14:40
https://nextcloud.com/blog/open-source- ... nextcloud/

Can't they pickup hMailServer development as well? :lol:
Linux only! :lol: :lol: :lol:
Don't think so.
It is written in PHP.

I'm a long term user of Nextcloud - love it.
They already have a web mail client called Snappy Mail that is an app inclusion, but exciting to see them get a hold of roundcube too.

Nextcloud is an offshoot or OwnCloud
Its not just php. You need to install docker on windows to run it, and also reverse proxy it if you have a webserver already running. It used to be php only and ran on windows + xampp. I did try it out many years ago. But at some point they gave up development for windows.

I've been using filerun, which is amazing. Very lightweight, fast, works well with webdav + nextcloud client. But they ended their free license so there will be no more updates unless you pay and the price is crazy - enterprise pricing. I would absolutely pay for 2 or 3 users if the price were reasonable. So I'm keeping my eye on nextcloud and owncloud.

Post Reply