CVE-2014-9465

Zarafa WebApp <2.0 beta 3 & ZCP 7.x <7.1.12 beta 1 & 7.2.x <7.2.0 b...

Title source: llm
STIX 2.1

Description

senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.

References (11)

Core 11
Core References
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:040
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/01/03/10
Various Sources x_refsource_confirm
https://jira.zarafa.com/browse/ZCP-12596
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156228.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/07/2
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156112.html
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2015-0049.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1139442

Scores

EPSS 0.0336
EPSS Percentile 87.4%

Details

CWE
CWE-399
Status published
Products (29)
fedoraproject/fedora 20
fedoraproject/fedora 21
zarafa/webapp < 2.0
zarafa/zarafa_collaboration_platform 7.0.0
zarafa/zarafa_collaboration_platform 7.0.1
zarafa/zarafa_collaboration_platform 7.0.2
zarafa/zarafa_collaboration_platform 7.0.3
zarafa/zarafa_collaboration_platform 7.0.4
zarafa/zarafa_collaboration_platform 7.0.5
zarafa/zarafa_collaboration_platform 7.0.6
... and 19 more
Published Feb 19, 2015
Tracked Since Feb 18, 2026