Impact
The Roundcube Webmail TNEF decoder, present before version 1.6.17 and before 1.7.2, can be forced into denial‑of‑service payload. The issue stems from a resource exhaustion scenario caused by an oversized data size in the decoder, leading to service slowdown or crash. This weakness is classified as CWE‑770, reflecting an out‑of‑memory condition that disrupts availability.
Affected Systems
Systems running Roundcube Webmail before 1.6.17 for the 1.6.x branch or before 1.7.2 for the 1.7.x branch are at risk. Updated versions 1.6.17 and later, and 1.7.2 and later, contain the fix.
Risk and Exploitability
The CVSS score is 4.3, and the EPSS score is less than 1%, which indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and requires an attacker to submit a malicious email through the webmail interface to trigger the DoS. Based on the description, the likely attack vector is via a crafted attachment containing a compressed‑RTF payload that the TNEF decoder processes, leading to resource exhaustion. Because it does not grant remote code execution or elevate privileges, the potential damage is limited to service disruption for users or administrators on the affected host.
OpenCVE Enrichment
Debian DLA
Debian DSA