CVE-2010-4767: Input Validation
Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, which allows remote attackers to cause a denial of service (duplicate tickets and duplicate auto-responses) by sending a crafted message to a POP3 mailbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4767?
CVE-2010-4767 has a medium severity rating, as it allows remote attackers to create denial of service conditions through duplicate tickets.
How do I fix CVE-2010-4767?
To fix CVE-2010-4767, upgrade OTRS to version 2.3.6 or later, where the vulnerability is addressed.
What are the affected versions of OTRS in CVE-2010-4767?
CVE-2010-4767 affects OTRS versions prior to 2.3.6, including various beta and release candidates prior to that version.
What kind of attack does CVE-2010-4767 facilitate?
CVE-2010-4767 facilitates attacks that can lead to denial of service by enabling duplicate tickets and auto-responses.
Are all OTRS versions vulnerable to CVE-2010-4767?
Not all OTRS versions are vulnerable; only versions before 2.3.6, including earlier beta releases, are affected by CVE-2010-4767.