Total vulnerabilities in the database
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
Software | From | Fixed in |
---|---|---|
kolab / kolab_groupware_server | 2.0.2 | 2.0.2.x |
kolab / kolab_groupware_server | - | 2005-12-15_pre2.1.x |
kolab / kolab_groupware_server | 2.0.1 | 2.0.1.x |