First published: Wed Mar 31 2021(Updated: )
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kopano Groupware Core | <=8.7.16 | |
Kopano Groupware Core | >=9.0.0<=9.1.0 | |
Kopano Groupware Core | >=10.0.0<=10.0.7 | |
Kopano Groupware Core | >=11.0.0<=11.0.1 | |
Zarafa Zarafa | >=6.30.0<=7.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28994 is a vulnerability in kopano-ical (formerly zarafa-ical) in Kopano Groupware Core, allowing memory exhaustion via long HTTP headers.
Kopano Groupware Core versions 8.7.16 through 11.0.1 and Zarafa versions 6.30.x through 7.2.x are affected by CVE-2021-28994.
CVE-2021-28994 has a severity rating of 7.5 (high).
To fix CVE-2021-28994, it is recommended to upgrade to a patched version of Kopano Groupware Core or Zarafa.
You can find more information about CVE-2021-28994 on the following references: [1](http://www.openwall.com/lists/oss-security/2021/04/01/1), [2](http://www.openwall.com/lists/oss-security/2021/04/25/1), [3](https://www.openwall.com/lists/oss-security/2021/03/19/6).