provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zarafa_collaboration_platform | Zarafa | * | 7.1.12 (including) |
Zarafa_collaboration_platform | Zarafa | 7.2.0 (including) | 7.2.0 (including) |