Release date:
Updated on:
Affected Systems:
Apple MacOS X Server 10.7.2
Apple MacOS X Server 10.7.1
Apple MacOS X Server 10.7
RoundCube Webmail 0.5.x
Unaffected system:
Apple MacOS X Server 10.7.3
RoundCube Webmail 0.5.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49229
Cve id: CVE-2011-2937
RoundCube Webmail is a browser-based IMAP client.
RoundCube Webmail has a cross-site scripting vulnerability. Attackers can exploit this vulnerability to execute arbitrary script code in the affected site user's browser to steal Cookie authentication creden.
<* Source: abyszko
Link: http://trac.roundcube.net/browser/tags/roundcubemail/v0.5.4/CHANGELOG
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/