Lucene search

K
mageiaGentoo FoundationMGASA-2015-0049
HistoryFeb 06, 2015 - 1:26 a.m.

Updated zarafa packages fix CVE-2014-9465 and some packaging issues

2015-02-0601:26:07
Gentoo Foundation
advisories.mageia.org
21

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.04

Percentile

92.2%

Updated zarafa packages fix security vulnerability: Robert Scheck discovered a flaw in Zarafa WebAccess >= 7.0.0 and Zarafa WebApp that could allow a remote unauthenticated attacker to exhaust the disk space of /tmp (CVE-2014-9465). This update also adds some patches from Robert Scheck which correct some packaging issues with zarafa-webaccess.

OSVersionArchitecturePackageVersionFilename
Mageia4noarchzarafa< 7.1.11-1.2zarafa-7.1.11-1.2.mga4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.04

Percentile

92.2%