CVE-2017-5944: Input Validation
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5944?
CVE-2017-5944 has been classified as a critical vulnerability as it allows remote authenticated users to execute arbitrary code.
How do I fix CVE-2017-5944?
To fix CVE-2017-5944, upgrade Request Tracker to versions 4.0.25, 4.2.14, or 4.4.2 and later.
Who is affected by CVE-2017-5944?
CVE-2017-5944 affects Request Tracker versions 4.0.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2.
What type of vulnerability is CVE-2017-5944?
CVE-2017-5944 is an arbitrary code execution vulnerability due to improper handling of crafted saved search names.
Can remote users exploit CVE-2017-5944?
Yes, authenticated remote users with certain privileges can exploit CVE-2017-5944.