Zarafa '/etc/zarafa/license/' Directory Multiple Local Information Disclosure Vulnerabilities
BID:69370
CVE-2014-5450 |Info
Zarafa '/etc/zarafa/license/' Directory Multiple Local Information Disclosure Vulnerabilities
| Bugtraq ID: | 69370 |
| Class: | Design Error |
| CVE: |
CVE-2014-5450 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2014 12:00AM |
| Updated: | Apr 13 2015 09:19PM |
| Credit: | Robert Scheck |
| Vulnerable: |
Zarafa Zarafa 7.1.10 Zarafa Zarafa 7.1.9 Zarafa Zarafa 7.1.8 Zarafa Zarafa 7.1.4 Zarafa Zarafa 7.0.13 Zarafa Zarafa 7.0.9 Zarafa Zarafa 7.0.8 Zarafa Zarafa 7.0.7 Zarafa Zarafa 6.40 0 Zarafa Zarafa 6.30.5 Zarafa Zarafa 6.30.4 Zarafa Zarafa 6.30 Zarafa Zarafa 7.1.3 Zarafa Zarafa 7.1.2 Zarafa Zarafa 7.1.1 Zarafa Zarafa 7.1.0 Zarafa Zarafa 7.0.6 Zarafa Zarafa 7.0.5 Zarafa Zarafa 7.0.4 Zarafa Zarafa 7.0.3 Zarafa Zarafa 7.0.2 Zarafa Zarafa 7.0.12 Zarafa Zarafa 7.0.11 Zarafa Zarafa 7.0.10 Zarafa Zarafa 7.0.1 Zarafa Zarafa 7.0 Zarafa Zarafa 6.40.9 Zarafa Zarafa 6.40.8 Zarafa Zarafa 6.40.7 Zarafa Zarafa 6.40.6 Zarafa Zarafa 6.40.5 Zarafa Zarafa 6.40.4 Zarafa Zarafa 6.40.3 Zarafa Zarafa 6.40.2 Zarafa Zarafa 6.40.17 Zarafa Zarafa 6.40.16 Zarafa Zarafa 6.40.15 Zarafa Zarafa 6.40.14 Zarafa Zarafa 6.40.13 Zarafa Zarafa 6.40.12 Zarafa Zarafa 6.40.11 Zarafa Zarafa 6.40.10 Zarafa Zarafa 6.30.9 Zarafa Zarafa 6.30.8 Zarafa Zarafa 6.30.7 Zarafa Zarafa 6.30.6 Zarafa Zarafa 6.30.3 Zarafa Zarafa 6.30.17 Zarafa Zarafa 6.30.16 Zarafa Zarafa 6.30.13 Zarafa Zarafa 6.30.11 Zarafa Zarafa 6.30.10 Zarafa Zarafa 6.20.7 Zarafa Zarafa 6.20.6 Zarafa Zarafa 6.20.5 Zarafa Zarafa 6.20.3 Zarafa Zarafa 6.20.2 Zarafa Zarafa 6.20.12 Zarafa Zarafa 6.20.11 Zarafa Zarafa 6.20.10 Zarafa Zarafa 6.20 Zarafa Zarafa 6.11 Zarafa Zarafa 6.10 Zarafa Zarafa 6.03 Zarafa Zarafa 6.02 Zarafa Zarafa 6.01 Zarafa Zarafa 6.00 Zarafa Zarafa 5.22 Zarafa Zarafa 5.20 Zarafa Zarafa 5.11 Zarafa Zarafa 5.10 Zarafa Zarafa 5.02 Zarafa Zarafa 5.01 Zarafa Zarafa 5.00 Zarafa Zarafa 4.1 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 |
| Not Vulnerable: | |
Discussion
Zarafa '/etc/zarafa/license/' Directory Multiple Local Information Disclosure Vulnerabilities
Zarafa is prone to multiple local information-disclosure vulnerabilities.
Local attackers can exploit these issues to obtain sensitive information. Information obtained may lead to further attacks.
Zarafa 4.1 and later are vulnerable.
Zarafa is prone to multiple local information-disclosure vulnerabilities.
Local attackers can exploit these issues to obtain sensitive information. Information obtained may lead to further attacks.
Zarafa 4.1 and later are vulnerable.
Exploit / POC
Zarafa '/etc/zarafa/license/' Directory Multiple Local Information Disclosure Vulnerabilities
Attackers can use standard, readily available tools to exploit these issues.
Attackers can use standard, readily available tools to exploit these issues.
Solution / Fix
Zarafa '/etc/zarafa/license/' Directory Multiple Local Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Mandriva Business Server 1 X86 64
-
Mandriva lib64zarafa-devel-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64zarafa0-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva php-mapi-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-MAPI-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-archiver-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-caldav-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-client-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-common-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-dagent-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-gateway-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-ical-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-indexer-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-monitor-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-server-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-spooler-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-utils-7.1.8-1.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva zarafa-webaccess-7.1.8-1.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/