Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled with a "Sign by default" queue configuration, uses a queue's key for signing, which might allow remote attackers to spoof messages by leveraging the lack of authentication semantics.
References
Link | Resource |
---|---|
http://lists.bestpractical.com/pipermail/rt-announce/2012-October/000212.html | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:15:28
Updated: 2022-10-03T16:15:28
Reserved: 2022-10-03T00:00:00
Link: CVE-2012-6578
JSON object: View
NVD Information
Status : Analyzed
Published: 2013-07-24T12:01:45.083
Modified: 2013-07-24T12:01:45.083
Link: CVE-2012-6578
JSON object: View
Redhat Information
No data.
CWE