Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-5057

Опубликовано: 18 мар. 2011
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

ignored

end of life
karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

released

2.3.4

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

debian
почти 15 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 d ...

github
больше 3 лет назад

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

5 Medium

CVSS2