First published: Thu Dec 05 2019(Updated: )
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=5.0.0<5.0.39 | |
Otrs Otrs | >=6.0.0<6.0.24 | |
Otrs Otrs | >=7.0.0<7.0.13 |
Upgrade to OTRS 7.0.13 or OTRS 6.0.24 or OTRS 5.0.39
Patch for ((OTRS)) Community Edition 6.0: https://github.com/OTRS/otrs/commit/799616eb43f7fb53cae4e04c81e2156baaf02e2b Patch for ((OTRS)) Community Edition 5.0: https://github.com/OTRS/otrs/commit/76b301f4e3f45cb23bb6a3d6907028c733d11145
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18180 is a vulnerability in ((OTRS)) Community Edition that allows a remote attacker to cause an endless loop by exploiting improper checks for filenames with overly long extensions in PostMaster or when uploading files.
((OTRS)) Community Edition versions 5.0.x, 6.0.x, and 7.0.x are affected by CVE-2019-18180.
CVE-2019-18180 has a severity score of 7.5 (high).
A remote attacker can exploit CVE-2019-18180 by sending emails with filenames that have overly long extensions or by uploading files with such filenames, causing an endless loop.
Yes, you can find references for CVE-2019-18180 at the following links: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html), [Link 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html)