CVE-2009-5057: Medium severity otrs vulnerability
The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5057?
CVE-2009-5057 is categorized as a high severity vulnerability due to its impact on cryptographic operations.
How do I fix CVE-2009-5057?
To fix CVE-2009-5057, update to OTRS version 2.3.4 or later, which properly configures the RANDFILE and HOME environment variables for OpenSSL.
What software versions are affected by CVE-2009-5057?
CVE-2009-5057 affects OTRS versions prior to 2.3.4 and several beta versions from 0.5 to 2.3.2.
What kind of attacks can exploit CVE-2009-5057?
CVE-2009-5057 can be exploited by remote attackers to potentially decrypt email messages due to compromised cryptographic operations.
Is there a workaround for CVE-2009-5057 if I can't update immediately?
A temporary workaround for CVE-2009-5057 involves manually configuring the RANDFILE and HOME environment variables for OpenSSL prior to invoking OTRS.