Vulnerability Description
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zarafa | Zarafa Collaboration Platform | <= 7.1.12 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159455.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159497.html
- http://www.securityfocus.com/bid/75104
- https://jira.zarafa.com/browse/ZCP-13282
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159455.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159497.html
- http://www.securityfocus.com/bid/75104
- https://jira.zarafa.com/browse/ZCP-13282
FAQ
What is CVE-2015-3436?
CVE-2015-3436 is a vulnerability with a CVSS score of 6.6 (MEDIUM). provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock...
How severe is CVE-2015-3436?
CVE-2015-3436 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3436?
Check the references section above for vendor advisories and patch information. Affected products include: Zarafa Zarafa Collaboration Platform.