7.5
CVSSv3

CVE-2021-28994

Published: 31/03/2021 Updated: 12/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core up to and including 8.7.16, 9.x up to and including 9.1.0, 10.x up to and including 10.0.7, and 11.x up to and including 11.0.1 and Zarafa 6.30.x up to and including 7.2.x allows memory exhaustion via long HTTP headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kopano groupware core

zarafa zarafa

Vendor Advisories

Debian Bug report logs - #986272 kopanocore: CVE-2021-28994 Package: src:kopanocore; Maintainer for src:kopanocore is Giraffe Maintainers <pkg-giraffe-maintainers@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 2 Apr 2021 09:00:01 UTC Severity: important Tags: security, ups ...

Mailing Lists

On Fri, 02 Apr 2021, Jan Engelhardt wrote: The affected Zarafa versions are identically to CVE-2021-28994 (verified), thus all versions since Zarafa 6300 Beta 1 (SVN Rev 13713) are affected Given the crash and error messages in old Zarafa versions look different than in more recent Zarafa/Kopano versions, here is how it looked for me when ve ...
On Friday 2021-03-19 13:44, Jan Engelhardt wrote: This was assigned CVE-2021-28994 ...