CVE-2014-1474: Medium severity best practical solutions request tracker vulnerability
Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1474?
CVE-2014-1474 is considered a moderate severity vulnerability due to its potential for denial of service.
How do I fix CVE-2014-1474?
To fix CVE-2014-1474, update Email::Address::List to version 0.02 or later and upgrade RT to version 4.2.3 or later.
What software is affected by CVE-2014-1474?
CVE-2014-1474 affects RT versions 4.2.0 to 4.2.2 and Email::Address::List versions up to 0.01.
What type of vulnerability is CVE-2014-1474?
CVE-2014-1474 is an algorithmic complexity vulnerability that allows a denial of service through excessive CPU consumption.
Can CVE-2014-1474 be exploited remotely?
Yes, CVE-2014-1474 can be exploited remotely by sending a specially crafted string that lacks an address.