CVE-2008-3395: Medium severity linux kernel vulnerability
Calacode @Mail 5.41 on Linux uses weak world-readable permissions for (1) webmail/libs/Atmail/Config.php and (2) webmail/webadmin/.htpasswd, which allows local users to obtain sensitive information by reading these files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3395?
CVE-2008-3395 is considered a moderate severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2008-3395?
To fix CVE-2008-3395, change the permissions of the affected files webmail/libs/Atmail/Config.php and webmail/webadmin/.htpasswd to restrict access only to authorized users.
What files are affected by CVE-2008-3395?
CVE-2008-3395 affects the files webmail/libs/Atmail/Config.php and webmail/webadmin/.htpasswd in Calacode Atmail 5.41.
Can local users exploit CVE-2008-3395?
Yes, local users can exploit CVE-2008-3395 by reading the world-readable configuration and password files to obtain sensitive information.
Is CVE-2008-3395 specific to Calacode Atmail 5.41?
Yes, CVE-2008-3395 specifically affects the Calacode Atmail version 5.41 on Linux systems.