CVE-2021-28994
https://notcve.org/view.php?id=CVE-2021-28994
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers. kopano-ical (anteriormente zarafa-ical) en Kopano Groupware Core versión hasta 8.7.16, 9.x hasta 9.1.0, 10.x hasta 10.0.7, y 11.xa hasta11.0.1 y Zarafa 6.30.x hasta 7.2.x, permite el agotamiento de la memoria a través de encabezados HTTP largos. • http://www.openwall.com/lists/oss-security/2021/04/01/1 http://www.openwall.com/lists/oss-security/2021/04/25/1 https://www.openwall.com/lists/oss-security/2021/03/19/6 • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2019-19907
https://notcve.org/view.php?id=CVE-2019-19907
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data. La función HrAddFBBlock en el archivo libfreebusy/freebusyutil.cpp en Kopano Groupware Core versiones anteriores a 8.7.7, permite un acceso fuera de límites, como es demostrado por el manejo inapropiado de una copia de matriz durante el análisis de datos ICal. • https://lists.debian.org/debian-lts-announce/2023/03/msg00006.html https://stash.kopano.io/projects/KC/repos/kopanocore/browse/RELNOTES.txt https://stash.kopano.io/projects/KC/repos/kopanocore/commits/4e02b420fff • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •