CVE-2010-0464
Mandriva Linux Security Advisory 2010-048
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.
Roundcube v0.3.1 y anteriores no solicitan que el navegador web permita el "prefetching" DNS de los nombres de dominio contenidos en mensajes de correo electrónico, lo que facilita a atacantes remotos determinar la localización de red del usuario de webmail mediante peticiones de logggin DNS.
Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests. The updated packages have been patched to correct this issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-01-29 CVE Reserved
- 2010-01-29 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://trac.roundcube.net/ticket/1486449 | 2015-08-24 |
URL | Date | SRC |
---|---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2010:048 | 2015-08-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | <= 0.3.1 Search vendor "Roundcube" for product "Webmail" and version " <= 0.3.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20050811 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20050820 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20051007 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | 20051021 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | beta2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | rc2 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1 Search vendor "Roundcube" for product "Webmail" and version "0.1" | stable |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.1.1 Search vendor "Roundcube" for product "Webmail" and version "0.1.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | alpha |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2 Search vendor "Roundcube" for product "Webmail" and version "0.2" | stable |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2.1 Search vendor "Roundcube" for product "Webmail" and version "0.2.1" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.2.2 Search vendor "Roundcube" for product "Webmail" and version "0.2.2" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | - |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | beta |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | rc1 |
Affected
| ||||||
Roundcube Search vendor "Roundcube" | Webmail Search vendor "Roundcube" for product "Webmail" | 0.3 Search vendor "Roundcube" for product "Webmail" and version "0.3" | stable |
Affected
|