Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Kerio MailServer / Connect < 7.0.1 Administration Console File Disclosure and File Corruption Vulnerability

Medium

Synopsis

The remote mail server is vulnerable to a file disclosure and corruption vulnerability.

Description

Versions of Kerio Mail Server / Connect earlier than 7.0.1 are potentially affected by a file disclosure and corruption vulnerability. An attacker, with full administrative rights, can modify the administrative console to change the product configuration to read or corrupt arbitrary files on the server.

Solution

Upgrade to Kerio Connect 7.0.1 or later.