[Bug 293904] mail/roundcube security update to 1.6.14

From: <bugzilla-noreply_at_freebsd.org>
Date: Wed, 18 Mar 2026 15:10:14 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293904

            Bug ID: 293904
           Summary: mail/roundcube security update to 1.6.14
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: ale@FreeBSD.org
          Reporter: filis@FreeBSD.org
          Assignee: ale@FreeBSD.org
             Flags: maintainer-feedback?(ale@FreeBSD.org)

Created attachment 268907
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=268907&action=edit
patch to update roundcube to 1.6.14

as of https://github.com/roundcube/roundcubemail/releases/tag/1.6.14

roundcube 1.6.14 contains a couple of security fixes:

- Fix pre-auth arbitrary file write via unsafe deserialization in
redis/memcache session handler, reported by y0us.
- Fix bug where a password could get changed without providing the old
password, reported by flydragon777.
- Fix IMAP Injection + CSRF bypass in mail search, reported by Martila Security
Research Team.
- Fix remote image blocking bypass via various SVG animate attributes, reported
by nullcathedral.
- Fix remote image blocking bypass via a crafted body background attribute,
reported by nullcathedral.
- Fix fixed position mitigation bypass via use of !important, reported by
nullcathedral.
- Fix XSS issue in a HTML attachment preview, reported by aikido_security.
- Fix SSRF + Information Disclosure via stylesheet links to a local network
hosts, reported by Georgios Tsimpidas (aka Frey), Security Researcher at
https://i0.rs/.

-- 
You are receiving this mail because:
You are the assignee for the bug.