Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:32
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 5.3 |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Broken Link | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Broken Link | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Broken Link | |
References | () https://community.otrs.com/security-advisory-2019-15-security-update-for-otrs-framework/ - Patch, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html - |
31 Aug 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-12-05 15:15
Updated : 2024-11-21 04:32
NVD link : CVE-2019-18180
Mitre link : CVE-2019-18180
CVE.ORG link : CVE-2019-18180
JSON object : View
Products Affected
otrs
- otrs
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')