UBUNTU-CVE-2021-28994

Source
https://ubuntu.com/security/CVE-2021-28994
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28994.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-28994
Upstream
  • CVE-2021-28994
Published
2021-03-31T23:15:00Z
Modified
2026-04-22T12:51:17.982307Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.

References

Affected packages

Ubuntu:Pro:18.04:LTS / kopanocore

Package

Name
kopanocore
Purl
pkg:deb/ubuntu/kopanocore@8.5.5-0ubuntu1+esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.1.0-3ubuntu5
8.1.0-3ubuntu6
8.3.4-4ubuntu4
8.5.2-1ubuntu1
8.5.5-0ubuntu1
8.5.5-0ubuntu1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-archiver"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-backup"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-common"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-contacts"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-core"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-dagent"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-gateway"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-ical"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-l10n"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-libs"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-monitor"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-presence"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-search"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-server"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-spooler"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "kopano-utils"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "php-mapi"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "php7.1-mapi"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "python-kopano"
        },
        {
            "binary_version": "8.5.5-0ubuntu1+esm1",
            "binary_name": "python-mapi"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28994.json"

Ubuntu:20.04:LTS / kopanocore

Package

Name
kopanocore
Purl
pkg:deb/ubuntu/kopanocore@8.7.0-7ubuntu1.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.7.0-3build2
8.7.0-5ubuntu5
8.7.0-5ubuntu6
8.7.0-6ubuntu1
8.7.0-6ubuntu2
8.7.0-6ubuntu3
8.7.0-7ubuntu1
8.7.0-7ubuntu1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-archiver"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-backup"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-common"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-contacts"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-core"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-dagent"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-gateway"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-ical"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-l10n"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-libs"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-monitor"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-presence"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-search"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-server"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-spamd"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-spooler"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "kopano-utils"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "php-mapi"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "python3-kopano"
        },
        {
            "binary_version": "8.7.0-7ubuntu1.1",
            "binary_name": "python3-mapi"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28994.json"

Ubuntu:22.04:LTS / kopanocore

Package

Name
kopanocore
Purl
pkg:deb/ubuntu/kopanocore@8.7.0-7.1ubuntu10.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.7.0-7.1ubuntu4
8.7.0-7.1ubuntu6
8.7.0-7.1ubuntu7
8.7.0-7.1ubuntu8
8.7.0-7.1ubuntu10
8.7.0-7.1ubuntu10.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-archiver"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-backup"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-common"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-contacts"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-core"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-dagent"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-gateway"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-ical"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-l10n"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-libs"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-monitor"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-presence"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-search"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-server"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-spamd"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-spooler"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "kopano-utils"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "php-mapi"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "python3-kopano"
        },
        {
            "binary_version": "8.7.0-7.1ubuntu10.1",
            "binary_name": "python3-mapi"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28994.json"