Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-7278

Опубликовано: 18 мар. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

ignored

end of life
karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

released

2.2.5, 2.3.0

Показывать по

Ссылки на источники

EPSS

Процентиль: 54%
0.00311
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 14 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

debian
больше 14 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, ...

github
больше 3 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

EPSS

Процентиль: 54%
0.00311
Низкий

5 Medium

CVSS2