Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2014/q3/444 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95453 | vdb entry |
http://advisories.mageia.org/MGASA-2014-0380.html | |
http://www.securityfocus.com/bid/69369 | vdb entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:182 | vendor advisory |
http://seclists.org/oss-sec/2014/q3/445 | mailing list |