CVE-2014-5447
Publication date 20 October 2014
Last updated 24 July 2024
Ubuntu priority
Description
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| zarafa | ||
| 14.04 LTS trusty | Not in release | |