REDHAT-BUG-1133439: Low severity Zarafa WebAccess vulnerability

Published Aug 25, 2014
·
Updated

Robert Scheck reported a number of issues with the default permissions in Zarafa[1]:

"" 1. In order to fix CVE-2014-0103, Zarafa introduced constants PASSWORDKEY and PASSWORDIV in /etc/zarafa/webaccess-ajax/config.php (Zarafa WebAccess) and /etc/zarafa/webapp/config.php (Zarafa WebApp), both are the upstream path names of a default installation, downstream names might be different. Both files have default permissions of root:root and 644, thus decryption of the symmetric encrypted passwords in the on-disk PHP session files is possible again (similar like initially described in CVE-2014-0103). Affects Zarafa WebAccess >= 7.1.10, Zarafa WebApp >= 1.6 beta.

2. The log directory /var/log/zarafa/ is shipped by default with root:root and 755 and all created log files by the Zarafa daemons have by default root:root and 644. This is leaking (depending on the log level of the given service) only e.g. subject, sender/recipient, message-id, SMTP queue id of in- and outbound e-mails but might be even a cleartext protocol dump of IMAP, POP3, CalDAV and iCal as well (including possible credentials) to any local system user. Affects Zarafa >= 5.00.

3. The directories /var/lib/zarafa-webaccess/tmp/ (Zarafa WebAccess) and /var/lib/zarafa-webapp/tmp/ (Zarafa WebApp) are read- and writable by the Apache system user by default - but also world readable for local system users (e.g. apache:apache and 755 on RHEL). Thus all the temporary session data such as uploaded e-mail attachments can be read-only accessed because all created files below previously mentioned directories have permissions 644, too. Upstream path names changed over the time and releases. Affects Zarafa WebAccess >= 4.1, Zarafa WebApp (any version).

4. The optional (but proprietary) license daemon /usr/bin/zarafa-licensed runs by default with root permissions, the subscription/license key is put into '/etc/zarafa/license/'. The license files are recommented (according upstream documentation) to be created using echo(1) which usually leads to root:root and 644. But the parent directory /etc/zarafa/license/ is shipped by default with root:root and 755. As result the key files can be accessed and copied by any local system user. Affects Zarafa >= 4.1. ""

[1] http://seclists.org/oss-sec/2014/q3/444

Affected Software

5 affected components
Zarafa WebAccess>=7.1.10
Zarafa webapp>=1.6
Zarafa Zarafa>=5.00
Zarafa WebAccess>=4.1
Zarafa webapp>=4.1

Event History

Aug 25, 2014
Data Sourced
07:22 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1133439?

The severity of REDHAT-BUG-1133439 is categorized as medium due to its implications for default permissions.

2

How do I fix REDHAT-BUG-1133439?

To fix REDHAT-BUG-1133439, ensure that proper permissions are set on the configuration files in Zarafa WebAccess.

3

What software is affected by REDHAT-BUG-1133439?

REDHAT-BUG-1133439 affects Zarafa WebAccess, Zarafa WebApp, and Zarafa Collaboration Platform.

4

Who reported REDHAT-BUG-1133439?

REDHAT-BUG-1133439 was reported by Robert Scheck.

5

Is there a patch for REDHAT-BUG-1133439?

Yes, a patch is available to address the issues reported in REDHAT-BUG-1133439.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203