Release date:
Updated on:
Affected Systems:
Zarafa Collaboration Platform <= 7.1.8
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65280
CVE (CAN) ID: CVE-2014-0037
Zarafa Collaboration Platform is an open source email and calendar component software.
The ValidateUserLogon function of Zarafa Collaboration Platform 7.1.8 and provider/libserver/ECSession. cpp in earlier versions allows remote attackers to exploit this vulnerability to cause denial-of-service (DoS) attacks by using NULL pointer methods.
<* Source: Robert Scheck (scheck@etes.de)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Zarafa
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.zarafa.com
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1059903