PT-2019-15258 · Otrs+2 · Otrs+3

Published

2019-12-05

·

Updated

2023-08-31

·

CVE-2019-18180

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OTRS Community Edition versions 5.0.38 and prior OTRS Community Edition versions 6.0.23 and prior OTRS versions 7.0.12 and prior
Description The issue is related to an improper check for filenames with overly long extensions in PostMaster, which can occur when sending emails or uploading files, such as attaching files to emails. This allows a remote attacker to cause an endless loop.
Recommendations For OTRS Community Edition versions 5.0.38 and prior, update to a version later than 5.0.38. For OTRS Community Edition versions 6.0.23 and prior, update to a version later than 6.0.23. For OTRS versions 7.0.12 and prior, update to a version later than 7.0.12. As a temporary workaround, consider restricting the upload of files with overly long extensions in PostMaster to minimize the risk of exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2649
ALT-PU-2020-2748
CVE-2019-18180
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Alt Linux
Otrs
Otrs Community Edition
Suse