|
|
>> Mandriva Security Update Kolab-server Information Disclosure Issue
|
Title : Mandriva Security Update Kolab-server Information Disclosure Issue VUPEN ID : VUPEN/ADV-2008-2570 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk 
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-09-16
|
A vulnerability has been identified in Mandriva, which could allow malicious users to gain knowledge of sensitive information. This issue is caused due to Kolab v1 using HTTP GET requests rather than HTTP POST requests and recording user passwords in the Apache log files, which could be exploited by local attackers with access to the Apache log files to harvest user passwords and possibly other sensitive data.
Affected Products
Mandriva Corporate 3.0
Solution
Upgrade the affected packages :
Corporate 3.0:
2dfff9159290939281e28939609ab5be corporate/3.0/i586/kolab-server-1.0-0.24.C30mdk.i586.rpm
5b687608b714691e169ab7e51cf6cc40 corporate/3.0/SRPMS/kolab-server-1.0-0.24.C30mdk.src.rpm
Corporate 3.0/X86_64:
fe1b25ea5465eaeb950f2e88878679af corporate/3.0/x86_64/kolab-server-1.0-0.24.C30mdk.x86_64.rpm
5b687608b714691e169ab7e51cf6cc40 corporate/3.0/SRPMS/kolab-server-1.0-0.24.C30mdk.src.rpm
References
http://www.vupen.com/english/advisories/2008/2570 http://archives.mandrivalinux.com/security-announce/2008-09/msg00015.php
ChangeLog
2008-09-16 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|