Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-2545

Опубликовано: 05 мая 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

5.0.7+dfsg-4
esm-apps/jammy

released

5.0.1+dfsg-1ubuntu1+esm1
esm-apps/noble

released

5.0.5+dfsg-2ubuntu0.1~esm1
esm-apps/resolute

not-affected

5.0.7+dfsg-4
esm-infra/focal

DNE

focal

DNE

jammy

needed

noble

needed

oracular

ignored

end of life, was needs-triage
plucky

released

5.0.7+dfsg-2ubuntu0.1

Показывать по

EPSS

Процентиль: 8%
0.00182
Низкий

Связанные уязвимости

nvd
больше 1 года назад

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

debian
больше 1 года назад

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior ...

github
больше 1 года назад

Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.

EPSS

Процентиль: 8%
0.00182
Низкий