Race condition in OTRS - CVE-2010-4765

 

Race condition in OTRS - CVE-2010-4765

Published: March 18, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45215
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2010-4765
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to manipulate or delete data.

Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic circumstances by creating tickets.


Affected software

OTRS

How to mitigate CVE-2010-4765

Install update from vendor's website.


External References

Related Security Bulletins