CVE-2012-6581
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to bypass intended restrictions on reading keys in the product's keyring, and trigger outbound e-mail messages signed by an arbitrary stored secret key, by leveraging a UI e-mail signing privilege.
Affected (17)
Products: Bestpractical: Request Tracker
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.8.10 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0.0 |
Related CWEs
References (2)
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.