CVE-2008-7280: Input Validation
Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System (OTRS) before 2.2.7 does not properly handle e-mail messages containing malformed UTF-8 characters, which allows remote attackers to cause a denial of service (e-mail retrieval outage) via a crafted message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7280?
CVE-2008-7280 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2008-7280?
To fix CVE-2008-7280, upgrade Open Ticket Request System (OTRS) to version 2.2.7 or later.
What systems are affected by CVE-2008-7280?
CVE-2008-7280 affects OTRS versions prior to 2.2.7 and several beta releases up to 2.1.9.
What type of attack does CVE-2008-7280 allow?
CVE-2008-7280 allows remote attackers to perform a denial of service by sending crafted email messages.
What component is impacted by CVE-2008-7280?
CVE-2008-7280 impacts the Kernel/System/EmailParser.pm component in OTRS.