Vulnerability Description
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kopano | Groupware Core | < 8.7.7 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2023/03/msg00006.html
- https://stash.kopano.io/projects/KC/repos/kopanocore/browse/RELNOTES.txtRelease Notes
- https://stash.kopano.io/projects/KC/repos/kopanocore/commits/4e02b420fffPatch
- https://lists.debian.org/debian-lts-announce/2023/03/msg00006.html
- https://stash.kopano.io/projects/KC/repos/kopanocore/browse/RELNOTES.txtRelease Notes
- https://stash.kopano.io/projects/KC/repos/kopanocore/commits/4e02b420fffPatch
FAQ
What is CVE-2019-19907?
CVE-2019-19907 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
How severe is CVE-2019-19907?
CVE-2019-19907 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19907?
Check the references section above for vendor advisories and patch information. Affected products include: Kopano Groupware Core.