MEDIUM
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature
Published Mar 18, 2011
5.0
MEDIUMCVSS 2.0
EPSS 1.47%
Description
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
Affected products
No data.
Configuration 1
Configuration 2
OR
- ≤ 2.4.9
- 0.5
- 0.5
- 0.5
- 0.5
- 0.5
- 0.5
- 0.5
- 0.5
- 1.0
- 1.0
- 1.0
- 1.0.0
- 1.0.1
- 1.0.2
- 1.1
- 1.1.0
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.2.0
- 1.2.0
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.1.0
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.5
- 2.2.6
- 2.2.7
- 2.2.8
- 2.2.9
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.0
- 2.3.1
- 2.3.2
- 2.3.3
- 2.3.4
- 2.3.5
- 2.3.6
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 2.4.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://bugs.otrs.org/show_bug.cgi?id=6131 x_refsource_CONFIRM
- http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://bugs.otrs.org/show_bug.cgi?id=6131 | x_refsource_CONFIRM | |
| http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 18, 2011
Updated Sep 16, 2024
Reserved Mar 18, 2011
Link CVE-2010-4764
CISA Vulnrichment
Updated n/a