Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kolab_groupware_server | Kolab | * | 2005-12-15_pre2.1 (including) |
Kolab_groupware_server | Kolab | 2.0.1 (including) | 2.0.1 (including) |
Kolab_groupware_server | Kolab | 2.0.2 (including) | 2.0.2 (including) |