Bug 1222151 (CVE-2015-3436) - CVE-2015-3436 zarafa: Overwrite arbitrary files in filesystem
Summary: CVE-2015-3436 zarafa: Overwrite arbitrary files in filesystem
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-3436
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: https://jira.zarafa.com/browse/ZCP-13282
Whiteboard: impact=low,public=20150519,reported=2...
Depends On: 1222909 1222911
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-05-15 21:52 UTC by Robert Scheck
Modified: 2019-06-08 20:35 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-08-22 03:29:02 UTC


Attachments (Terms of Use)
Relevant difference between Zarafa 7.2.0 and 7.2.1 beta 1 (1.47 KB, patch)
2015-05-18 21:09 UTC, Robert Scheck
no flags Details | Diff
Backport of the patch from 7.2.1 beta 1 for Zarafa 7.1.x (1.49 KB, patch)
2015-05-18 21:56 UTC, Robert Scheck
no flags Details | Diff

Description Robert Scheck 2015-05-15 21:52:41 UTC
Guido Günther detected and reported that replacing "/tmp/zarafa-upgrade-lock"
by a symlink makes the zarafa-server process following that symlink and thus 
allows to overwrite arbitrary files in the filesystem (assuming zarafa-server
runs as root which is not case by default at Fedora, but upstream default).
One just needs write permissions in /tmp and wait until the zarafa-server is
restarted.

Comment 1 Robert Scheck 2015-05-15 21:53:04 UTC
Zarafa fixed this issue with version 7.2.1 beta 1, however they unfortunately
did not release any source code files nor a source code patch so far. At
https://download.zarafa.com/community/beta/7.2/7.2.1-49597/ the "sourcecode"
directory is missing.

Comment 2 Robert Scheck 2015-05-18 21:09:10 UTC
Created attachment 1026883 [details]
Relevant difference between Zarafa 7.2.0 and 7.2.1 beta 1

Meanwhile Zarafa has published the source code of Zarafa 7.2.1 beta 1.

Comment 3 Robert Scheck 2015-05-18 21:56:52 UTC
Created attachment 1026887 [details]
Backport of the patch from 7.2.1 beta 1 for Zarafa 7.1.x

Backport takes proper care of reworked log levels from 7.1.x to 7.2.x.

Comment 4 Martin Prpič 2015-05-19 12:29:53 UTC
Created zarafa tracking bugs for this issue:

Affects: fedora-all [bug 1222909]
Affects: epel-all [bug 1222911]

Comment 5 Fedora Update System 2015-06-03 15:45:28 UTC
zarafa-7.1.12-2.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2015-06-03 15:46:10 UTC
zarafa-7.1.12-2.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2015-06-03 15:47:32 UTC
zarafa-7.1.12-2.el5, php53-mapi-7.1.12-2.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2015-06-05 23:41:37 UTC
zarafa-7.1.12-2.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2015-06-05 23:48:12 UTC
zarafa-7.1.12-2.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.