CVE-2008-7278: Input Validation
The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7278?
CVE-2008-7278 is classified as a medium severity vulnerability due to its potential to allow remote attackers to decrypt email messages.
How do I fix CVE-2008-7278?
To fix CVE-2008-7278, upgrade your Open Ticket Request System (OTRS) to version 2.2.5 or later.
What versions of OTRS are affected by CVE-2008-7278?
CVE-2008-7278 affects OTRS versions prior to 2.2.5 and 2.3.x before 2.3.0-beta1.
What does CVE-2008-7278 impact in OTRS?
CVE-2008-7278 impacts the S/MIME feature in OTRS, specifically related to improper configuration of the RANDFILE environment variable.
Can CVE-2008-7278 lead to unauthorized access?
Yes, CVE-2008-7278 can potentially allow unauthorized access to email messages due to decreased encryption strength.