CVE-2019-19907

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
19/12/2019
Last modified:
06/03/2023

Description

HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kopano:groupware_core:*:*:*:*:*:*:*:* 8.7.7 (excluding)