CVE-2010-3476

NameCVE-2010-3476
DescriptionOpen Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 does not properly handle the matching of Perl regular expressions against HTML e-mail messages, which allows remote attackers to cause a denial of service (CPU consumption) via a large message, a different vulnerability than CVE-2010-2080.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
otrs2sourcelenny(not affected)
otrs2source(unstable)2.4.8+dfsg1-1

Notes

[lenny] - otrs2 <not-affected> (Only affects OTRS 2.3 and 2.4)

Search for package or bug name: Reporting problems