First published: Fri Mar 18 2011(Updated: )
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =2.4.0-beta6 | |
OTRS | =2.4.0-beta5 | |
OTRS | =2.0.0-beta4 | |
OTRS | =2.0.0-beta2 | |
OTRS | =2.3.0-beta2 | |
OTRS | =2.4.1 | |
OTRS | =2.1.3 | |
OTRS | =2.2.4 | |
OTRS | =2.2.5 | |
OTRS | <=2.4.6 | |
OTRS | =1.0.2 | |
OTRS | =2.4.5 | |
OTRS | =2.3.5 | |
OTRS | =2.1.8 | |
OTRS | =1.1.1 | |
OTRS | =2.3.0-beta1 | |
OTRS | =0.5-beta1 | |
OTRS | =1.2.0-beta2 | |
OTRS | =1.2.0-beta3 | |
OTRS | =1.3.1 | |
OTRS | =2.2.0-beta3 | |
OTRS | =2.0.0-beta5 | |
OTRS | =2.1.5 | |
OTRS | =2.3.4 | |
OTRS | =2.1.2 | |
OTRS | =0.5-beta4 | |
OTRS | =0.5-beta7 | |
OTRS | =1.3.0-beta4 | |
OTRS | =2.2.0-beta4 | |
OTRS | =2.4.0-beta3 | |
OTRS | =2.0.3 | |
OTRS | =1.1.0-rc1 | |
OTRS | =1.1-rc1 | |
OTRS | =0.5-beta2 | |
OTRS | =2.1.0-beta1 | |
OTRS | =2.3.0-beta4 | |
OTRS | =1.2.1 | |
OTRS | =2.2.0-beta1 | |
OTRS | =2.2.6 | |
OTRS | =2.3.3 | |
OTRS | =2.0.0 | |
OTRS | =1.1.4 | |
OTRS | =0.5-beta6 | |
OTRS | =2.2.0-beta2 | |
OTRS | =0.5-beta3 | |
OTRS | =1.2.3 | |
OTRS | =2.4.0-beta2 | |
OTRS | =2.2.2 | |
OTRS | =2.4.3 | |
OTRS | =2.3.1 | |
OTRS | =1.0.1 | |
OTRS | =1.2.4 | |
OTRS | =2.0.0-beta1 | |
OTRS | =2.0.5 | |
OTRS | =1.1.2 | |
OTRS | =2.2.0-rc1 | |
OTRS | =0.5-beta8 | |
OTRS | =2.2.9 | |
OTRS | =2.1.6 | |
OTRS | =1.3.2 | |
OTRS | =2.1.0-beta2 | |
OTRS | =1.2.2 | |
OTRS | =2.4.0-beta4 | |
OTRS | =1.0-rc1 | |
OTRS | =1.3.0-beta1 | |
OTRS | =2.4.4 | |
OTRS | =2.1.7 | |
OTRS | =2.4.2 | |
OTRS | =2.0.4 | |
OTRS | =1.3.0-beta3 | |
OTRS | =1.3.0-beta2 | |
OTRS | =2.1.9 | |
OTRS | =2.2.7 | |
OTRS | =2.2.1 | |
OTRS | =1.1.3 | |
OTRS | =2.1.4 | |
OTRS | =1.0.0 | |
OTRS | =2.3.2 | |
OTRS | =2.3.0-rc1 | |
OTRS | =2.1.1 | |
OTRS | =2.0.2 | |
OTRS | =2.0.1 | |
OTRS | =2.4.0-beta1 | |
OTRS | =1.1.0-rc2 | |
OTRS | =2.2.3 | |
OTRS | =2.3.0-beta3 | |
OTRS | =2.0.0-beta6 | |
OTRS | =1.3.3 | |
OTRS | =2.2.8 | |
OTRS | =1.0-rc2 | |
OTRS | =2.3.6 | |
OTRS | =1.0-rc3 | |
OTRS | =1.2.0-beta1 | |
OTRS | =0.5-beta5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4766 has a medium severity level due to its potential to expose sensitive information via improperly handled inline images in forwarded messages.
To fix CVE-2010-4766, update to a patched version of Open Ticket Request System (OTRS) 2.4.7 or later where the issue is resolved.
CVE-2010-4766 can expose potentially sensitive image information contained in HTML e-mail messages.
CVE-2010-4766 affects OTRS versions before 2.4.7, including various beta and stable releases prior to that version.
Users who rely on OTRS versions prior to 2.4.7 could be affected, as attackers may exploit the vulnerability to access sensitive image data.