CVE-2015-6566: Fedoraproject Fedora

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.

Affected products

  • Fedoraproject Fedora: version 21 only
  • Zarafa Zarafa Collaboration Platform: up to and including 7.2.0

Published 2016-01-11. Last modified 2026-06-17.