PT-2005-5489 · Kolab · Kolab Server
Published
2005-12-31
·
Updated
2010-04-02
·
CVE-2005-4828
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kolab Server versions 2.0.0 through 2.0.1
Description
The issue is related to the handling of large emails with a "." in the wrong place, which causes kolabfilter to add another ".", potentially breaking clear-text signatures and attachments. It is unclear whether this issue crosses privilege boundaries.
Recommendations
For Kolab Server versions 2.0.0 through 2.0.1, consider restricting the handling of large emails or the use of kolabfilter until a proper fix is available.
At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kolab Server