First published: Mon Mar 19 2018(Updated: )
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zarafa Collaboration Platform | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5450 is considered a moderate severity vulnerability due to the exposure of sensitive information.
To fix CVE-2014-5450, change the permissions of the /etc/zarafa/license file to restrict access.
CVE-2014-5450 allows local users to read sensitive license information stored in the zarafa license file.
CVE-2014-5450 specifically affects Zarafa Collaboration Platform version 4.1.
No, CVE-2014-5450 requires local access to exploit the vulnerability.