Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clear-text signatures and attachments. NOTE: it is not clear whether this issue crosses privilege boundaries, so this might not be a vulnerability.
Link | Tags |
---|---|
http://kolab.org/security/kolab-vendor-notice-07.txt | exploit |
http://www.mandriva.com/security/advisories?name=MDKSA-2006:013 | vendor advisory |
http://www.osvdb.org/22538 | vdb entry |