First published: Fri Jan 31 2020(Updated: )
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | <=7.4.1 | |
Open-Xchange App Suite Backend | =7.4.2 | |
Open-Xchange App Suite Backend | =7.4.2-revision1 | |
Open-Xchange App Suite Backend | =7.4.2-revision10 | |
Open-Xchange App Suite Backend | =7.4.2-revision2 | |
Open-Xchange App Suite Backend | =7.4.2-revision3 | |
Open-Xchange App Suite Backend | =7.4.2-revision4 | |
Open-Xchange App Suite Backend | =7.4.2-revision5 | |
Open-Xchange App Suite Backend | =7.4.2-revision6 | |
Open-Xchange App Suite Backend | =7.4.2-revision7 | |
Open-Xchange App Suite Backend | =7.4.2-revision8 | |
Open-Xchange App Suite Backend | =7.4.2-revision9 | |
Open-Xchange App Suite Backend | =7.6.0 | |
Open-Xchange App Suite Backend | =7.6.0-revision1 | |
Open-Xchange App Suite Backend | =7.6.0-revision2 | |
Open-Xchange App Suite Backend | =7.6.0-revision3 | |
Open-Xchange App Suite Backend | =7.6.0-revision4 | |
Open-Xchange App Suite Backend | =7.6.0-revision5 | |
Open-Xchange App Suite Backend | =7.6.0-revision6 | |
Open-Xchange App Suite Backend | =7.6.0-revision7 | |
Open-Xchange App Suite Backend | =7.6.0-revision8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.