Input validation error in Debian Linux - CVE-2019-12248

 

Input validation error in Debian Linux - CVE-2019-12248

Published: June 17, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35827
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12248
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. An attacker could send a malicious email to an OTRS system. If a logged-in agent user quotes it, the email could cause the browser to load external image resources.


Affected software

Debian Linux
otrs (Alpine package)

How to mitigate CVE-2019-12248

Install update from vendor's website.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins