PT-2017-8926 · Inverse+1 · Sogo+1

Jens Erat

·

Published

2016-02-27

·

Updated

2022-12-20

·

CVE-2016-6188

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SOGo version 2.3.7
Description A memory leak issue allows remote attackers to cause a denial of service by consuming memory via a large number of attempts to upload a large attachment, related to temporary files.
Recommendations For SOGo version 2.3.7, consider restricting the size of attachments that can be uploaded to prevent excessive memory consumption until a patch is available. As a temporary workaround, monitor system resources closely to detect and mitigate potential denial-of-service attacks.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1171
CVE-2016-6188

Affected Products

Alt Linux
Sogo