Roundcube Community Forum

 

Moxieplayer.swf security vulnerability?

Started by jkirker, May 18, 2015, 08:48:57 PM

Previous topic - Next topic

jkirker

All of my servers which run Roundcube started chirping at me today due to a maldet/clamv detection.

Here's an example - any thoughts?

FILE HIT LIST:
{CAV}BC.Exploit.CVE_2013_5329 : /var/www/html/roundcubemail-1.1.1/program/js/tinymce/plugins/media/moxieplayer.swf => /usr/local/maldetect/quarantine/moxieplayer.swf.11180

Sorry if I posted this in the wrong area but I figured it was worth posting.  WordPress also uses this file by default as part of TinyMCE.