Name | CVE-2025-2545 |
Description | Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-4157-1, DSA-5909-1, DSA-5911-1 |
Debian Bugs | 1104422, 1104424 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
request-tracker4 (PTS) | bullseye | 4.4.4+dfsg-2+deb11u3 | vulnerable |
bullseye (security) | 4.4.4+dfsg-2+deb11u4 | fixed | |
bookworm, bookworm (security) | 4.4.6+dfsg-1.1+deb12u2 | fixed | |
sid | 4.4.7+dfsg-4 | vulnerable | |
request-tracker5 (PTS) | bookworm, bookworm (security) | 5.0.3+dfsg-3~deb12u3 | fixed |
trixie | 5.0.7+dfsg-3 | fixed | |
sid | 5.0.7+dfsg-4 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
request-tracker4 | source | bullseye | 4.4.4+dfsg-2+deb11u4 | DLA-4157-1 | ||
request-tracker4 | source | bookworm | 4.4.6+dfsg-1.1+deb12u2 | DSA-5911-1 | ||
request-tracker4 | source | (unstable) | (unfixed) | 1104424 | ||
request-tracker5 | source | bookworm | 5.0.3+dfsg-3~deb12u3 | DSA-5909-1 | ||
request-tracker5 | source | (unstable) | 5.0.7+dfsg-3 | 1104422 |
Fixed by: https://github.com/bestpractical/rt/commit/a5042a30aaa0fcf4255d0a06ee2659d302742fc3 (rt-4.4.8)
Fixed by: https://github.com/bestpractical/rt/commit/a63c2534b3227de5be820cf4c1e4088dc0203020 (rt-5.0.8)