[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-6190 -- sogo

ID: oval:org.secpod.oval:def:1900532Date: (C)2019-02-28   (M)2023-12-20
Class: VULNERABILITYFamily: unix




SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UIDand DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time"restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
sogo
Reference:
CVE-2016-6190
CVE    1
CVE-2016-6190
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:sogo:sogo

© SecPod Technologies