Security update for roundcubemail
This update for roundcubemail fixes one security issues and two bugs.
The following vulnerability was fixed:
- CVE-2017-8114: Authenticated users may have reset arbitrary passwords (boo#1036955)
The following upstream bugs were fixed:
- Fix regression in LDAP fuzzy search where it always used prefix search instead
- Fix bug where base_dn setting was ignored inside group_filters
- Submitted by Andreas Stieger (AndreasStieger)
Fixed bugs
bnc#1036955
VUL-0: CVE-2017-8114: roundcubemail: RCW allows arbitrary password resets by authenticated users