CVE-2019-18180: Denial of service
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2019-18180?
CVE-2019-18180 is a vulnerability in ((OTRS)) Community Edition that allows a remote attacker to cause an endless loop by exploiting improper checks for filenames with overly long extensions in PostMaster or when uploading files.
Which versions of ((OTRS)) Community Edition are affected by CVE-2019-18180?
((OTRS)) Community Edition versions 5.0.x, 6.0.x, and 7.0.x are affected by CVE-2019-18180.
What is the severity of CVE-2019-18180?
CVE-2019-18180 has a severity score of 7.5 (high).
How can a remote attacker exploit CVE-2019-18180?
A remote attacker can exploit CVE-2019-18180 by sending emails with filenames that have overly long extensions or by uploading files with such filenames, causing an endless loop.
Are there any references for CVE-2019-18180?
Yes, you can find references for CVE-2019-18180 at the following links: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html), [Link 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html)