CVE-2010-4764: Medium severity otrs vulnerability
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4764?
CVE-2010-4764 has a medium severity rating as it allows attackers to spoof email communication due to the lack of warnings about revoked PGP or GPG keys.
How do I fix CVE-2010-4764?
To mitigate CVE-2010-4764, upgrade to OTRS version 2.4.10, 3.0.3, or later where the issue is addressed.
What systems are affected by CVE-2010-4764?
CVE-2010-4764 affects OTRS versions prior to 2.4.10 and any 3.x releases before 3.0.3.
What is the main issue with CVE-2010-4764?
The main issue with CVE-2010-4764 is the failure to alert users regarding incoming encrypted emails that are based on revoked keys, facilitating potential spoofing.
Who can be impacted by CVE-2010-4764?
Users of OTRS systems that rely on PGP or GPG encryption for email communications are at risk from CVE-2010-4764.