PT-2018-14861 · Roundcube+2 · Roundcube+2

CVE-2018-19205

·

Published

2018-10-06

·

Updated

2026-03-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Roundcube versions prior to 1.3.7
Description The issue makes it easier for attackers to obtain sensitive information by mishandling GnuPG MDC integrity-protection warnings. This is related to the handling of encryption and decryption processes, specifically in the context of plugins/enigma/lib/enigma driver gnupg.php.
Recommendations For versions prior to 1.3.7, update to version 1.3.7 or later to resolve the issue. As a temporary workaround, consider disabling the use of GnuPG MDC integrity-protection until a patch is applied. Restrict access to sensitive information to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2424
CVE-2018-19205
USN-8132-1

Affected Products

Alt Linux
Roundcube
Ubuntu