Roundcube Community Forum

Miscellaneous => Roundcube Discussion => Topic started by: jkirker on May 18, 2015, 08:48:57 PM

Title: Moxieplayer.swf security vulnerability?
Post by: jkirker on May 18, 2015, 08:48:57 PM
All of my servers which run Roundcube started chirping at me today due to a maldet/clamv detection.

Here's an example - any thoughts?

FILE HIT LIST:
{CAV}BC.Exploit.CVE_2013_5329 : /var/www/html/roundcubemail-1.1.1/program/js/tinymce/plugins/media/moxieplayer.swf => /usr/local/maldetect/quarantine/moxieplayer.swf.11180

Sorry if I posted this in the wrong area but I figured it was worth posting.  WordPress also uses this file by default as part of TinyMCE.