CVE-2010-3476
Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 does not properly handle the matching of Perl regular expressions against HTML e-mail messages, which allows remote attackers to cause a denial of service (CPU consumption) via…
Does this matter?
Lower severity and a low EPSS score (2.52%). Track it; it rarely justifies an emergency change on its own.
Description
Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 does not properly handle the matching of Perl regular expressions against HTML e-mail messages, which allows remote attackers to cause a denial of service (CPU consumption) via a large message, a different vulnerability than CVE-2010-2080.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- otrs/otrs
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://otrs.org/advisory/OSA-2010-02-en/Vendor Advisory
- http://secunia.com/advisories/41381Vendor Advisory
- http://security-tracker.debian.org/tracker/CVE-2010-2080
- http://www.securityfocus.com/bid/43264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61869
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html
- http://otrs.org/advisory/OSA-2010-02-en/Vendor Advisory
- http://secunia.com/advisories/41381Vendor Advisory
- http://security-tracker.debian.org/tracker/CVE-2010-2080
- http://www.securityfocus.com/bid/43264
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61869
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.