CVE-2026-62642
בינונית 6.5
תיאור (מקור, אנגלית)
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-835
מוצרים מושפעים
roundcube: webmail
קישורים
- https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2 Vendor Advisory
- https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf8… Patch
- https://github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070c… Patch
- https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b48… Patch
- https://github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d02… Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.17 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.2 Release Notes