Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6189

Опубликовано: 17 фев. 2017
Источник: debian
EPSS Низкий

Описание

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sogofixed3.2.4-0.2package
sogoend-of-lifewheezypackage

Примечания

  • Fix SOGo v2: https://github.com/inverse-inc/sogo/commit/717f45f640a2866b76a8984139391fae64339225 (SOGo-2.3.12)

  • Fix SOGo v3: https://github.com/inverse-inc/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d (SOGo-3.1.1)

  • https://sogo.nu/bugs/view.php?id=3695

EPSS

Процентиль: 39%
0.00173
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 9 лет назад

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

CVSS3: 4.3
nvd
почти 9 лет назад

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

CVSS3: 4.3
github
больше 3 лет назад

Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

EPSS

Процентиль: 39%
0.00173
Низкий