First published: Mon Oct 20 2014(Updated: )
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zarafa WebAccess | =4.1 | |
Zarafa WebApp |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5449 has a medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2014-5449, restrict the permissions of the tmp directory to ensure that sensitive session data is not world-readable.
CVE-2014-5449 affects Zarafa WebAccess 4.1 and the Zarafa WebApp due to insecure file permissions.
Yes, local users can exploit CVE-2014-5449 to read sensitive session data due to world-readable permissions.
Yes, CVE-2014-5449 remains a concern if vulnerable versions of Zarafa software are still in use without appropriate security measures.