← Back

CVE-2015-3436

nvd nist
Published: Jun 9, 2015Modified: May 6, 2026

JSON object

Loading...
6.6
Vector
AV:L/AC:L/Au:N/C:N/I:C/A:C
Exploitability: 3.9 / Impact: 9.2
Source: NVD

Description

provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

Affected (2)

1 product
Zarafa Collaboration Platform
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Zarafa
Up to 7.1.12
Version 7.2.0

Timeline

No history available yet.