Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.
History

Thu, 17 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Znuny
Znuny znuny
Weaknesses CWE-1333
CPEs cpe:2.3:a:znuny:znuny:*:*:*:*:-:*:*:*
cpe:2.3:a:znuny:znuny:*:*:*:*:lts:*:*:*
Vendors & Products Znuny
Znuny znuny
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 15 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
Description Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-11T00:00:00

Updated: 2024-10-15T18:47:17.273Z

Reserved: 2024-10-09T00:00:00

Link: CVE-2024-48938

cve-icon Vulnrichment

Updated: 2024-10-15T18:45:19.978Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-11T21:15:07.387

Modified: 2024-10-17T19:49:56.327

Link: CVE-2024-48938

cve-icon Redhat

No data.