PT-2005-5489 · Kolab · Kolab Server

Published

2005-12-31

·

Updated

2010-04-02

·

CVE-2005-4828

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kolab Server versions 2.0.0 through 2.0.1
Description The issue is related to the handling of large emails with a "." in the wrong place, which causes kolabfilter to add another ".", potentially breaking clear-text signatures and attachments. It is unclear whether this issue crosses privilege boundaries.
Recommendations For Kolab Server versions 2.0.0 through 2.0.1, consider restricting the handling of large emails or the use of kolabfilter until a proper fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4828

Affected Products

Kolab Server