CVE-2014-9472: High severity Debian Debian Linux vulnerability
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9472?
CVE-2014-9472 is categorized as a denial of service vulnerability, which can lead to high CPU and disk consumption.
How do I fix CVE-2014-9472?
To mitigate CVE-2014-9472, upgrade Your Request Tracker version to at least 4.0.23 or 4.2.10.
Who is affected by CVE-2014-9472?
CVE-2014-9472 affects versions of Request Tracker from 3.0.0 up to 4.0.22 and 4.2.x up to 4.2.9.
What kind of attacks exploit CVE-2014-9472?
CVE-2014-9472 can be exploited by remote attackers sending crafted emails that cause increased resource consumption.
Is there a workaround for CVE-2014-9472 if I cannot upgrade?
A potential workaround for CVE-2014-9472 would be to implement email filtering rules or rate limiting to block malformed emails.