CVE-2010-4764
published 2011-03-18CVE-2010-4764: Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.47%
70.4th percentile
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | otrs2 | < otrs2 2.4.10+dfsg1-1 (bullseye) | otrs2 2.4.10+dfsg1-1 (bullseye) |
| otrs | otrs | <= 2.4.9 | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-4764: otrs2 - Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not ...
vendor_debian·2010·CVSS 5.0
CVE-2010-4764 [MEDIUM] CVE-2010-4764: otrs2 - Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not ...
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
Scope: local
bullseye: resolved (fixed in 2.4.10+dfsg1-1)
GHSA
GHSA-6gv9-qq2x-7jw6: Open Ticket Request System (OTRS) before 2
ghsa_unreviewed·2022-05-17
CVE-2010-4764 [MEDIUM] GHSA-6gv9-qq2x-7jw6: Open Ticket Request System (OTRS) before 2
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
OSV
CVE-2010-4764: Open Ticket Request System (OTRS) before 2
osv·2011-03-18·CVSS 5.0
CVE-2010-4764 [MEDIUM] CVE-2010-4764: Open Ticket Request System (OTRS) before 2
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.
No detection rules found.
No public exploits indexed.
2011-03-18
Published