CVE-2019-10740
published 2019-04-07CVE-2019-10740: In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.77%
51.5th percentile
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | roundcube | < roundcube 1.3.10+dfsg.1-1 (bookworm) | roundcube 1.3.10+dfsg.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| roundcube | roundcube_webmail | >= 0 < 1.2~beta+dfsg.1-0ubuntu1+esm7 | 1.2~beta+dfsg.1-0ubuntu1+esm7 |
| roundcube | roundcube_webmail | >= 0 < 1.3.6+dfsg.1-1ubuntu0.1~esm7 | 1.3.6+dfsg.1-1ubuntu0.1~esm7 |
| roundcube | webmail | < 1.3.10 | 1.3.10 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Roundcube Webmail vulnerabilities
vendor_ubuntu·2026-03-30·CVSS 6.1
CVE-2018-19205 [MEDIUM] Roundcube Webmail vulnerabilities
Title: Roundcube Webmail vulnerabilities
Summary: Several security issues were fixed in Roundcube Webmail.
It was discovered that Roundcube Webmail did not properly sanitize
certain HTML elements within the e-mail body. An attacker could possibly
use this issue to cause a cross-site scripting attack. This issue was only
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)
It was discovered that Roundcube Webmail did not properly handle certain
configuration parameters. An attacker could possibly use this issue to
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2016-9920)
It was discovered that Roundcube Webmail did not properly sanitize CSS styles
within SVG documents. An attacker could possibly use this issue to cause
a cross-site scripting att
Debian
CVE-2019-10740: roundcube - In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP e...
vendor_debian·2019·CVSS 4.3
CVE-2019-10740 [MEDIUM] CVE-2019-10740: roundcube - In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP e...
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Scope: local
bookworm: resolved (fixed in 1.3.10+dfsg.1-1)
bullseye: resolved (fixed in 1.3.10+dfsg.1-1)
forky: resolved (fixed in 1.3.10+dfsg.1-1)
sid: resolved (fixed in 1.3.10+dfsg.1-1)
trixie: resolved (fixed in 1.3.10+dfsg.1-1)
OSV
roundcube vulnerabilities
osv·2026-03-30·CVSS 6.1
CVE-2016-4068 [MEDIUM] roundcube vulnerabilities
roundcube vulnerabilities
It was discovered that Roundcube Webmail did not properly sanitize
certain HTML elements within the e-mail body. An attacker could possibly
use this issue to cause a cross-site scripting attack. This issue was only
addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)
It was discovered that Roundcube Webmail did not properly handle certain
configuration parameters. An attacker could possibly use this issue to
execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2016-9920)
It was discovered that Roundcube Webmail did not properly sanitize CSS styles
within SVG documents. An attacker could possibly use this issue to cause
a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.
(CVE-2017-6820)
It was di
GHSA
GHSA-8x8m-cq38-629v: In Roundcube Webmail before 1
ghsa_unreviewed·2022-05-04
CVE-2019-10740 [MEDIUM] CWE-319 GHSA-8x8m-cq38-629v: In Roundcube Webmail before 1
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
OSV
CVE-2019-10740: In Roundcube Webmail before 1
osv·2019-04-07·CVSS 4.3
CVE-2019-10740 [MEDIUM] CVE-2019-10740: In Roundcube Webmail before 1
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10740 roundcubemail: information disclosure of encrypted message [epel-all]
bugzilla·2019-04-15·CVSS 4.3
CVE-2019-10740 [MEDIUM] CVE-2019-10740 roundcubemail: information disclosure of encrypted message [epel-all]
CVE-2019-10740 roundcubemail: information disclosure of encrypted message [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2019-10740 roundcubemail: information disclosure of encrypted message
bugzilla·2019-04-15·CVSS 4.3
CVE-2019-10740 [MEDIUM] CVE-2019-10740 roundcubemail: information disclosure of encrypted message
CVE-2019-10740 roundcubemail: information disclosure of encrypted message
In Roundcube Webmail 1.3.4, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Reference:
https://github.com/roundcube/roundcubemail/issues/6638
Discussion:
Created roundcubemail tracking bugs for this issue:
Affects: epel-all [bug 1699751]
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.htmlhttps://github.com/roundcube/roundcubemail/issues/6638https://github.com/roundcube/roundcubemail/releases/tag/1.3.10https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFFMSO5WKEYSGMTZPZFF4ZADUJ57PRN5/http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00083.htmlhttps://github.com/roundcube/roundcubemail/issues/6638https://github.com/roundcube/roundcubemail/releases/tag/1.3.10https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TFFMSO5WKEYSGMTZPZFF4ZADUJ57PRN5/
2019-04-07
Published