Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2011/1071 | vdb entry |
http://lists.bestpractical.com/pipermail/rt-announce/2011-April/000188.html | patch mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=696795 | patch |
http://blog.bestpractical.com/2011/04/security-vulnerabilities-in-rt.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/66794 | vdb entry |
http://www.securityfocus.com/bid/47383 | vdb entry |
http://lists.bestpractical.com/pipermail/rt-announce/2011-April/000187.html | patch mailing list |
http://lists.bestpractical.com/pipermail/rt-announce/2011-April/000189.html | patch mailing list |
http://www.debian.org/security/2011/dsa-2220 | vendor advisory |
http://secunia.com/advisories/44189 | third party advisory vendor advisory |