CVE-2008-7278
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.
La función S/MIME en Open Ticket Request System (OTRS) anterior a v2.2.5, y v2.3.x anteriores a v2.3.0-beta1, no configura correctamente la variable de entorno RANDFILE para OpenSSL, lo que podría facilitar a los atacantes remotos descifrar mensajes de correo electrónico que tenían menos entropía de la previsto para operaciones de cifrado, relacionado con la imposibilidad de escribir en el fichero de generación de semilla para claves.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-03-18 CVE Reserved
- 2011-03-18 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.otrs.org/show_bug.cgi?id=2539 | 2011-03-22 | |
http://bugs.otrs.org/show_bug.cgi?id=2844 | 2011-03-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | <= 2.2.4 Search vendor "Otrs" for product "Otrs" and version " <= 2.2.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta7 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta8 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.0 Search vendor "Otrs" for product "Otrs" and version "1.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.1 Search vendor "Otrs" for product "Otrs" and version "1.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.2 Search vendor "Otrs" for product "Otrs" and version "1.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1 Search vendor "Otrs" for product "Otrs" and version "1.1" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.1 Search vendor "Otrs" for product "Otrs" and version "1.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.2 Search vendor "Otrs" for product "Otrs" and version "1.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.3 Search vendor "Otrs" for product "Otrs" and version "1.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.4 Search vendor "Otrs" for product "Otrs" and version "1.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.1 Search vendor "Otrs" for product "Otrs" and version "1.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.2 Search vendor "Otrs" for product "Otrs" and version "1.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.3 Search vendor "Otrs" for product "Otrs" and version "1.2.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.4 Search vendor "Otrs" for product "Otrs" and version "1.2.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.1 Search vendor "Otrs" for product "Otrs" and version "1.3.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.2 Search vendor "Otrs" for product "Otrs" and version "1.3.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.3 Search vendor "Otrs" for product "Otrs" and version "1.3.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.1 Search vendor "Otrs" for product "Otrs" and version "2.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.2 Search vendor "Otrs" for product "Otrs" and version "2.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.3 Search vendor "Otrs" for product "Otrs" and version "2.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.4 Search vendor "Otrs" for product "Otrs" and version "2.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.5 Search vendor "Otrs" for product "Otrs" and version "2.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.1 Search vendor "Otrs" for product "Otrs" and version "2.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.2 Search vendor "Otrs" for product "Otrs" and version "2.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.3 Search vendor "Otrs" for product "Otrs" and version "2.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.4 Search vendor "Otrs" for product "Otrs" and version "2.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.5 Search vendor "Otrs" for product "Otrs" and version "2.1.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.6 Search vendor "Otrs" for product "Otrs" and version "2.1.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.7 Search vendor "Otrs" for product "Otrs" and version "2.1.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.8 Search vendor "Otrs" for product "Otrs" and version "2.1.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.9 Search vendor "Otrs" for product "Otrs" and version "2.1.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.1 Search vendor "Otrs" for product "Otrs" and version "2.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.2 Search vendor "Otrs" for product "Otrs" and version "2.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.3 Search vendor "Otrs" for product "Otrs" and version "2.2.3" | - |
Affected
|