{"id":"UBUNTU-CVE-2023-46267","details":"** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-5631. Reason: This candidate is a duplicate of CVE-2023-5631. Notes: All CVE users should reference CVE-2023-5631 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.","modified":"2025-07-08T14:32:28.128544Z","published":"2023-10-20T04:15:00Z","withdrawn":"2025-07-08T10:46:52Z","upstream":["CVE-2023-46267"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-46267"},{"type":"REPORT","url":"https://github.com/roundcube/roundcubemail/commit/41756cc3331b495cc0b71886984474dc529dd31d"},{"type":"REPORT","url":"https://github.com/roundcube/roundcubemail/issues/9168"},{"type":"REPORT","url":"https://github.com/roundcube/roundcubemail/compare/1.5.4...1.5.5"},{"type":"REPORT","url":"https://roundcube.net/news/2023/10/16/security-update-1.6.4-released"},{"type":"REPORT","url":"https://github.com/roundcube/roundcubemail/compare/1.4.14...1.4.15"},{"type":"REPORT","url":"https://roundcube.net/news/2023/10/16/security-updates-1.5.5-and-1.4.15"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-46267"}],"affected":[{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.2~beta+dfsg.1-0ubuntu1+esm6?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.1+dfsg.1-2","1.1.2+dfsg.1-5","1.1.3+dfsg.1-1","1.1.4+dfsg.1-1","1.2~beta+dfsg.1-0ubuntu1","1.2~beta+dfsg.1-0ubuntu1+esm1","1.2~beta+dfsg.1-0ubuntu1+esm2","1.2~beta+dfsg.1-0ubuntu1+esm3","1.2~beta+dfsg.1-0ubuntu1+esm4","1.2~beta+dfsg.1-0ubuntu1+esm5","1.2~beta+dfsg.1-0ubuntu1+esm6"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46267.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.3.6+dfsg.1-1ubuntu0.1~esm5?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.0+dfsg.1-1","1.3.1+dfsg.1-1","1.3.3+dfsg.1-1","1.3.3+dfsg.1-2","1.3.6+dfsg.1-1","1.3.6+dfsg.1-1ubuntu0.1~esm1","1.3.6+dfsg.1-1ubuntu0.1~esm2","1.3.6+dfsg.1-1ubuntu0.1~esm3","1.3.6+dfsg.1-1ubuntu0.1~esm4","1.3.6+dfsg.1-1ubuntu0.1~esm5"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46267.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.4.3+dfsg.1-1ubuntu0.1~esm5?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.8+dfsg.1-2","1.3.10+dfsg.1-1","1.4.1+dfsg.1-2","1.4.2+dfsg.1-1","1.4.2+dfsg.1-2","1.4.3+dfsg.1-1","1.4.3+dfsg.1-1ubuntu0.1~esm1","1.4.3+dfsg.1-1ubuntu0.1~esm2","1.4.3+dfsg.1-1ubuntu0.1~esm3","1.4.3+dfsg.1-1ubuntu0.1~esm4","1.4.3+dfsg.1-1ubuntu0.1~esm5"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46267.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.5.0+dfsg.1-2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.11+dfsg.1-4","1.5.0+dfsg.1-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46267.json"}}],"schema_version":"1.7.3","severity":[{"score":"medium"}]}