Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3551-1 otrs2 security update
EUVD EUVD EUVD-2019-7985 Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
Fixes

Solution

Upgrade to OTRS 7.0.13 or OTRS 6.0.24 or OTRS 5.0.39


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T19:24:26.216Z

Reserved: 2019-10-17T00:00:00

Link: CVE-2019-18180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-05T15:15:11.420

Modified: 2024-11-21T04:32:46.717

Link: CVE-2019-18180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.