CVE-2019-19907: Critical severity kopano groupware core vulnerability
Published Dec 19, 2019
·Updated
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
Affected Software
4 affected componentsFixes available
Kopano Groupware Core<8.7.7
debian/kopanocore
ubuntu/kopanocore<8.5.5-0ubuntu1+
8.5.5-0ubuntu1+
ubuntu/kopanocore<8.7.0-6
8.7.0-6
Remediation
Event History
Dec 19, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 4, 2024
Data Sourced
via Launchpad·05:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19907?
CVE-2019-19907 has a medium severity due to the potential for out-of-bounds access in Kopano Groupware Core.
2
How do I fix CVE-2019-19907?
To fix CVE-2019-19907, upgrade Kopano Groupware Core to version 8.7.7 or later.
3
What versions of Kopano Groupware Core are affected by CVE-2019-19907?
CVE-2019-19907 affects all versions of Kopano Groupware Core prior to 8.7.7.
4
What is the impact of CVE-2019-19907 on my system?
The impact of CVE-2019-19907 could allow an attacker to exploit the out-of-bounds access to potentially manipulate memory.
5
Are there any specific distributions impacted by CVE-2019-19907?
Yes, the CVE-2019-19907 vulnerability impacts Kopano Groupware Core installations on various distributions including Debian and Ubuntu.