USN-8097-1 fixed a vulnerability in roundcube. The update caused a regression affecting the HTML sanitizer, preventing Roundcube from rendering any email message body. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack.
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube"
},
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube-core"
},
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube-mysql"
},
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube-pgsql"
},
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube-plugins"
},
{
"binary_version": "1.4.3+dfsg.1-1ubuntu0.1~esm7",
"binary_name": "roundcube-sqlite3"
}
]
}