Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2181
Reference (s):
- BID:96391
- URL: http://www.securityfocus.com/bid/96391
- https://github.com/roundcube/roundcubemail/issues/4757

