CVE-2015-6566: Fedoraproject Fedora
High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
Affected products
- Fedoraproject Fedora: version 21 only
- Zarafa Zarafa Collaboration Platform: up to and including 7.2.0
Published 2016-01-11. Last modified 2026-06-17.