CVE-2014-0103
published 2014-07-29CVE-2014-0103: WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
31.0th percentile
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| zarafa | webapp | <= 1.5 | — |
| zarafa | webapp | — | — |
| zarafa | zarafa | <= 7.1.9 | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
| zarafa | zarafa | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w227-7r9m-46hc: WebAccess in Zarafa before 7
ghsa_unreviewed·2022-05-17
CVE-2014-0103 [LOW] GHSA-w227-7r9m-46hc: WebAccess in Zarafa before 7
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
GHSA
GHSA-327v-7xhm-qrxf: Zarafa WebAccess 7
ghsa_unreviewed·2022-05-17·CVSS 2.1
CVE-2014-5447 [LOW] CWE-200 GHSA-327v-7xhm-qrxf: Zarafa WebAccess 7
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
Red Hat
samba: potential DoS in the internal DNS server
vendor_redhat·2014-05-28·CVSS 5.0
CVE-2014-0239 [MEDIUM] samba: potential DoS in the internal DNS server
samba: potential DoS in the internal DNS server
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103.
Statement: Not vulnerable. This issue does not affect the version of samba as shipped with Red Hat Enterprise Linux 5 and 6. This issue does not affect the version of samba3x as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of samba4 as shipped with Red Hat Enterprise Linux 6.
Package: samba (Red Hat Enterprise Linux 4) - Not affected
Package: samba (Red Hat Enterpri
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5447 CVE-2014-5448 CVE-2014-5449 CVE-2014-5450 zarafa: multiple default permission issues
bugzilla·2014-08-25·CVSS 2.1
CVE-2014-5447 [LOW] CVE-2014-5447 CVE-2014-5448 CVE-2014-5449 CVE-2014-5450 zarafa: multiple default permission issues
CVE-2014-5447 CVE-2014-5448 CVE-2014-5449 CVE-2014-5450 zarafa: multiple default permission issues
Robert Scheck reported a number of issues with the default permissions in Zarafa[1]:
""
1. In order to fix CVE-2014-0103, Zarafa introduced constants PASSWORD_KEY
and PASSWORD_IV in /etc/zarafa/webaccess-ajax/config.php (Zarafa WebAccess)
and /etc/zarafa/webapp/config.php (Zarafa WebApp), both are the upstream
path names of a default installation, downstream names might be different.
Both files have default permissions of root:root and 644, thus decryption
of the symmetric encrypted passwords in the on-disk PHP session files is
possible again (similar like initially described in CVE-2014-0103). Affects
Zarafa WebAccess >= 7.1.10, Zarafa WebApp >= 1.6 beta.
2. The log directory /var/log/zar
Bugzilla
CVE-2014-0103 zarafa: passwords stored in cleartext on server [epel-all]
bugzilla·2014-06-04·CVSS 2.1
CVE-2014-0103 [LOW] CVE-2014-0103 zarafa: passwords stored in cleartext on server [epel-all]
CVE-2014-0103 zarafa: passwords stored in cleartext on server [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-0103 zarafa: passwords stored in cleartext on server [fedora-all]
bugzilla·2014-06-04·CVSS 2.1
CVE-2014-0103 [LOW] CVE-2014-0103 zarafa: passwords stored in cleartext on server [fedora-all]
CVE-2014-0103 zarafa: passwords stored in cleartext on server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2014-0103 zarafa: passwords stored in cleartext on server
bugzilla·2014-03-06·CVSS 2.1
CVE-2014-0103 [LOW] CVE-2014-0103 zarafa: passwords stored in cleartext on server
CVE-2014-0103 zarafa: passwords stored in cleartext on server
Robert Scheck reported that Zarafa's WebAccess stored session information, including login credentials, on-disk in PHP session files. This session file would contain a user's username and password to the Zarafa IMAP server.
If Zarafa WebAccess was run on a shared hosting site (multiple web sites on the same server), and an administrator of another server, with the ability to upload arbitrary scripts to the server, they could use this to obtain these IMAP credentials due to both sites being run by the same Apache user, and the PHP session files being owned by the same.
In a non-shared hosting environment, or one using something like SuEXEC, where the PHP session files are owned by individual users on a per-site basis, this wou
Bugzilla
CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
bugzilla·2014-01-06·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
A job usage issue in several APIs could allow an attacker who is able to establish a read-only connection to libvirtd to crash libvirtd.
Discussion:
Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=db86da5ca2109e4006c286a09b6c75bfe10676ad
https://bugzilla.redhat.com/show_bug.cgi?id=1043069#c15 notes "I found similar patterns in several other APIs and fixed them by the following commits: v1.2.0-233-gb799259, v1.2.0-234-gf93d2ca, v1.2.0-235-gff5f30b, v1.2.0-236-g3b56425."
---
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1054206]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2014:0103 https://rhn.redhat.com/errata/RHSA
http://advisories.mageia.org/MGASA-2014-0380.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-July/136033.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-July/136044.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:182http://www.securityfocus.com/bid/68247https://bugzilla.redhat.com/show_bug.cgi?id=1073618http://advisories.mageia.org/MGASA-2014-0380.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-July/136033.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-July/136044.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2014:182http://www.securityfocus.com/bid/68247https://bugzilla.redhat.com/show_bug.cgi?id=1073618
2014-07-29
Published