Lucene search

K
cveMitreCVE-2014-9472
HistoryMar 09, 2015 - 2:59 p.m.

CVE-2014-9472

2015-03-0914:59:02
CWE-399
mitre
web.nvd.nist.gov
40
email gateway
rt
remote attackers
denial of service
crafted email

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

8

Confidence

High

EPSS

0.014

Percentile

86.6%

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.

Affected configurations

Nvd
Node
debiandebian_linuxMatch7.0
Node
fedoraprojectfedoraMatch21
OR
fedoraprojectfedoraMatch22
Node
bestpracticalrequest_trackerMatch3.6.8
OR
bestpracticalrequest_trackerMatch3.6.10
OR
bestpracticalrequest_trackerMatch3.6.11
OR
bestpracticalrequest_trackerMatch3.8.3
OR
bestpracticalrequest_trackerMatch3.8.4
OR
bestpracticalrequest_trackerMatch3.8.7
OR
bestpracticalrequest_trackerMatch3.8.9
OR
bestpracticalrequest_trackerMatch3.8.10
OR
bestpracticalrequest_trackerMatch3.8.11
OR
bestpracticalrequest_trackerMatch3.8.12
OR
bestpracticalrequest_trackerMatch3.8.13
OR
bestpracticalrequest_trackerMatch3.8.14
OR
bestpracticalrequest_trackerMatch3.8.15
OR
bestpracticalrequest_trackerMatch3.8.16
OR
bestpracticalrequest_trackerMatch3.8.17
OR
bestpracticalrequest_trackerMatch4.0.0
OR
bestpracticalrequest_trackerMatch4.0.1
OR
bestpracticalrequest_trackerMatch4.0.2
OR
bestpracticalrequest_trackerMatch4.0.3
OR
bestpracticalrequest_trackerMatch4.0.4
OR
bestpracticalrequest_trackerMatch4.0.5
OR
bestpracticalrequest_trackerMatch4.0.6
OR
bestpracticalrequest_trackerMatch4.0.7
OR
bestpracticalrequest_trackerMatch4.0.8
OR
bestpracticalrequest_trackerMatch4.0.9
OR
bestpracticalrequest_trackerMatch4.0.10
OR
bestpracticalrequest_trackerMatch4.0.11
OR
bestpracticalrequest_trackerMatch4.0.12
OR
bestpracticalrequest_trackerMatch4.0.13
OR
bestpracticalrequest_trackerMatch4.0.14
OR
bestpracticalrequest_trackerMatch4.0.15
OR
bestpracticalrequest_trackerMatch4.0.16
OR
bestpracticalrequest_trackerMatch4.0.17
OR
bestpracticalrequest_trackerMatch4.0.18
OR
bestpracticalrequest_trackerMatch4.0.19
OR
bestpracticalrequest_trackerMatch4.0.20
OR
bestpracticalrequest_trackerMatch4.0.21
OR
bestpracticalrequest_trackerMatch4.0.22
OR
bestpracticalrequest_trackerMatch4.2.0
OR
bestpracticalrequest_trackerMatch4.2.1
OR
bestpracticalrequest_trackerMatch4.2.2
OR
bestpracticalrequest_trackerMatch4.2.3
OR
bestpracticalrequest_trackerMatch4.2.4
OR
bestpracticalrequest_trackerMatch4.2.5
OR
bestpracticalrequest_trackerMatch4.2.6
OR
bestpracticalrequest_trackerMatch4.2.7
OR
bestpracticalrequest_trackerMatch4.2.8
OR
bestpracticalrequest_trackerMatch4.2.9
VendorProductVersionCPE
debiandebian_linux7.0cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
fedoraprojectfedora21cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
fedoraprojectfedora22cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.6.8cpe:2.3:a:bestpractical:request_tracker:3.6.8:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.6.10cpe:2.3:a:bestpractical:request_tracker:3.6.10:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.6.11cpe:2.3:a:bestpractical:request_tracker:3.6.11:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.8.3cpe:2.3:a:bestpractical:request_tracker:3.8.3:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.8.4cpe:2.3:a:bestpractical:request_tracker:3.8.4:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.8.7cpe:2.3:a:bestpractical:request_tracker:3.8.7:*:*:*:*:*:*:*
bestpracticalrequest_tracker3.8.9cpe:2.3:a:bestpractical:request_tracker:3.8.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 511

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

8

Confidence

High

EPSS

0.014

Percentile

86.6%