Impact
An infinite loop in the TNEF decoder causes the Roundcube Webmail process to consume excessive CPU resources until it becomes unresponsive, preventing users from accessing their webmail until the service is manually restarted or the process restarts automatically. This flaw does not provide code execution or data exfiltration; it merely disrupts availability of the affected instance. The weakness is identified as CWE‑835, highlighting loop control logic problems that can exhaust system resources.
Affected Systems
Roundcube Webmail is affected. Versions before 1.6.17 in the 1.6 series and before 1.7.2 in the 1.7 series contain the vulnerable TNEF decoder, exposing any installation running those releases to denial‑of‑service when a malicious TNEF attachment is opened by an authenticated or unauthenticated user via the webmail interface.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker must trigger the decoder by delivering an email with a TNEF attachment which the user then opens, representing an external attack vector that results in service disruption without compromising confidentiality or integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA