CVE-2019-18180

Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

History

31 Aug 2023, 03:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html -

27 Jan 2023, 15:19

Type Values Removed Values Added
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Broken Link
CPE cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

Information

Published : 2019-12-05 15:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-18180

Mitre link : CVE-2019-18180

CVE.ORG link : CVE-2019-18180


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')