Skip to content

Commit d1f3308

Browse files
Curtis StewartCurtis Stewart
authored andcommitted
Fixed a security issue with roundcube.
1 parent 93eb420 commit d1f3308

File tree

3 files changed

+10
-0
lines changed

3 files changed

+10
-0
lines changed

install/hst-install-debian.sh

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1538,9 +1538,11 @@ if [ "$dovecot" = 'yes' ] && [ "$exim" = 'yes' ] && [ "$mysql" = 'yes' ]; then
15381538
chown www-data:adm /var/log/roundcube/errors
15391539

15401540
r="$(gen_pass)"
1541+
rcDesKey="$(openssl rand -base64 30 | tr -d "/" | cut -c1-24)"
15411542
mysql -e "CREATE DATABASE roundcube"
15421543
mysql -e "GRANT ALL ON roundcube.*
15431544
TO roundcube@localhost IDENTIFIED BY '$r'"
1545+
sed -i "s/vtIOjLZo9kffJoqzpSbm5r1r/$rcDesKey/g" /etc/roundcube/config.inc.php
15441546
sed -i "s/%password%/$r/g" /etc/roundcube/debian-db-roundcube.php
15451547
sed -i "s/localhost/$servername/g" /etc/roundcube/plugins/password/config.inc.php
15461548
mysql roundcube < /usr/share/dbconfig-common/data/roundcube/install/mysql

install/hst-install-ubuntu.sh

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1487,10 +1487,12 @@ if [ "$dovecot" = 'yes' ] && [ "$exim" = 'yes' ] && [ "$mysql" = 'yes' ]; then
14871487
chown www-data:adm /var/log/roundcube/errors
14881488

14891489
r="$(gen_pass)"
1490+
rcDesKey="$(openssl rand -base64 30 | tr -d "/" | cut -c1-24)"
14901491
mysql -e "CREATE DATABASE roundcube"
14911492
mysql -e "GRANT ALL ON roundcube.*
14921493
TO roundcube@localhost IDENTIFIED BY '$r'"
14931494
sed -i "s/%password%/$r/g" /etc/roundcube/debian-db-roundcube.php
1495+
sed -i "s/vtIOjLZo9kffJoqzpSbm5r1r/$rcDesKey/g" /etc/roundcube/config.inc.php
14941496
sed -i "s/localhost/$servername/g" /etc/roundcube/plugins/password/config.inc.php
14951497
mysql roundcube < /usr/share/dbconfig-common/data/roundcube/install/mysql
14961498

install/upgrade/versions/latest.sh

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,3 +113,9 @@ if [ -z "$GZIP_LVL_CHECK" ]; then
113113
echo "(*) Updating backup compression level variable..."
114114
$BIN/v-change-sys-config-value "BACKUP_GZIP" '9'
115115
fi
116+
117+
# Randomize Rouncube des_key for better security
118+
if [ -f "/etc/roundcube/config.inc.php" ]; then
119+
rcDesKey="$(openssl rand -base64 30 | tr -d "/" | cut -c1-24)"
120+
sed -i "s/vtIOjLZo9kffJoqzpSbm5r1r/$rcDesKey/g" /etc/roundcube/config.inc.php
121+
fi

0 commit comments

Comments
 (0)