First published: Thu Dec 19 2019(Updated: )
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kopano Groupware Core | <8.7.7 | |
debian/kopanocore | ||
ubuntu/kopanocore | <8.5.5-0ubuntu1+ | 8.5.5-0ubuntu1+ |
ubuntu/kopanocore | <8.7.0-6 | 8.7.0-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19907 has a medium severity due to the potential for out-of-bounds access in Kopano Groupware Core.
To fix CVE-2019-19907, upgrade Kopano Groupware Core to version 8.7.7 or later.
CVE-2019-19907 affects all versions of Kopano Groupware Core prior to 8.7.7.
The impact of CVE-2019-19907 could allow an attacker to exploit the out-of-bounds access to potentially manipulate memory.
Yes, the CVE-2019-19907 vulnerability impacts Kopano Groupware Core installations on various distributions including Debian and Ubuntu.