The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CPJVDT77ZPRU5Z2BEMZM7EBY6WZHUATZ/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YR46PPHBEM76DNN4DEQMAYIKLCO3TQU2/ | vendor advisory |
https://bestpractical.com/download-page | release notes product |
https://lists.debian.org/debian-lts-announce/2020/02/msg00009.html | third party advisory mailing list |
https://usn.ubuntu.com/4517-1/ | third party advisory vendor advisory |