The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.otrs.org/show_bug.cgi?id=3462 - Patch | |
References | () http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 - |
Information
Published : 2011-03-18 16:55
Updated : 2024-11-21 01:11
NVD link : CVE-2009-5057
Mitre link : CVE-2009-5057
CVE.ORG link : CVE-2009-5057
JSON object : View
Products Affected
otrs
- otrs
CWE
CWE-310
Cryptographic Issues