• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.

Forwarded to devs Roundcube security updates 1.3.3, 1.2.7 and 1.1.10 released

prprtl

New Pleskian
TITLE:
Roundcube security updates 1.3.3, 1.2.7 and 1.1.10 released
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE:
Plesk all versions
PROBLEM DESCRIPTION:
Important security updates are released for Roundcube. Plesk should update their packages as well. Exploits are already seen in the wild.

We just published updates to all stable versions from 1.1.x onwards
delivering fixes for a recently discovered file disclosure
vulnerability in Roundcube Webmail.

Apparently this zero-day exploit is already being used by hackers to
read Roundcube’s configuration files. It requires a valid
username/password as the exploit only works with a valid session. More
details will be published soon under CVE-2017-16651.


See [Roundcube Announce] Security updates 1.3.3, 1.2.7 and 1.1.10 released
STEPS TO REPRODUCE:
Install Roundcube through Plesk​
ACTUAL RESULT:
Vulnerable version installed​
EXPECTED RESULT:
Security update applied​
ANY ADDITIONAL INFORMATION:
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM:
Confirm bug
 
Thank you for report.
The update of roundcube for Plesk 17.5, 17.0, 12.5 and 12.0 is scheduled to nearest updates.
 
Back
Top