DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.
Solution:
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://otrs.com/release-notes/otrs-security-advisory-2021-09/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html | mailing list |