CVE-2010-4759: Input Validation
Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4759?
CVE-2010-4759 is considered to have a moderate severity level as it allows remote authenticated users to cause a denial of service.
How do I fix CVE-2010-4759?
To fix CVE-2010-4759, it is recommended to upgrade to OTRS version 3.0.0-beta7 or later which addresses this vulnerability.
What versions of OTRS are affected by CVE-2010-4759?
CVE-2010-4759 affects multiple versions of OTRS including 2.4.0-beta6, 2.4.1, and earlier releases.
What type of attack does CVE-2010-4759 facilitate?
CVE-2010-4759 facilitates a denial of service attack through unmanaged fulltext searches by authenticated users.
Is there a workaround for CVE-2010-4759 while waiting for a patch?
Currently, there are no documented workarounds for CVE-2010-4759, so the best course of action is to upgrade to a secure version.