CVE-2016-6188: Medium severity SOGo vulnerability
Published Feb 3, 2017
·Updated
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporary files.
Affected Software
1 affected component
SOGo=2.3.7
Remediation
Event History
Feb 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6188?
CVE-2016-6188 is considered to be of moderate severity due to its potential to cause a denial of service through memory consumption.
2
How do I fix CVE-2016-6188?
To mitigate CVE-2016-6188, upgrade SOGo to version 2.3.8 or later where the memory leak issue has been resolved.
3
Who is affected by CVE-2016-6188?
CVE-2016-6188 affects SOGo version 2.3.7, allowing remote attackers to exploit the vulnerability.
4
What type of attack does CVE-2016-6188 allow?
CVE-2016-6188 allows remote attackers to perform denial of service attacks by uploading large attachments repeatedly.
5
Is CVE-2016-6188 a local or remote vulnerability?
CVE-2016-6188 is a remote vulnerability that does not require local access to exploit.