CVE-2012-6579
Last modified
CVE-2012-6579 is a vulnerability of currently unknown severity. Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cause a denial of service (loss of e-mail readability), via an e-mail message to a queue's address.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cause a denial of service (loss of e-mail readability), via an e-mail message to a queue's address.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bestpractical | Request Tracker | 3.8.3 |
| Bestpractical | Request Tracker | 3.8.4 |
| Bestpractical | Request Tracker | 3.8.7 |
| Bestpractical | Request Tracker | 3.8.9 |
| Bestpractical | Request Tracker | 3.8.10 |
| Bestpractical | Request Tracker | 3.8.11 |
| Bestpractical | Request Tracker | 3.8.12 |
| Bestpractical | Request Tracker | 3.8.13 |
| Bestpractical | Request Tracker | 3.8.14 |
| Bestpractical | Request Tracker | 4.0.0 |
| Bestpractical | Request Tracker | 4.0.1 |
| Bestpractical | Request Tracker | 4.0.2 |
| Bestpractical | Request Tracker | 4.0.3 |
| Bestpractical | Request Tracker | 4.0.4 |
| Bestpractical | Request Tracker | 4.0.5 |
| Bestpractical | Request Tracker | 4.0.6 |
| Bestpractical | Request Tracker | 4.0.7 |
References
- http://lists.bestpractical.com/pipermail/rt-announce/2012-October/000212.htmlPatch, Vendor Advisory
- http://lists.bestpractical.com/pipermail/rt-announce/2012-October/000212.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6579?
How severe is CVE-2012-6579?
How do I fix CVE-2012-6579?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6573Cross-site scripting (XSS) vulnerability in the Apache Solr …
- CVE-2012-6574Cross-site scripting (XSS) vulnerability in the Fonecta veri…
- CVE-2012-6575Cross-site scripting (XSS) vulnerability in the Exposed Filt…
- CVE-2012-6576Cross-site scripting (XSS) vulnerability in the PRH Search m…
- CVE-2012-6577SQL injection vulnerability in the Formhandler extension bef…
- CVE-2012-6578Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x be…
- CVE-2012-6580Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x be…
- CVE-2012-6581Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x be…
- CVE-2012-6582Cross-site scripting (XSS) vulnerability in the Spambot modu…
- CVE-2012-6583Cross-site scripting (XSS) vulnerability in the Imagemenu mo…
- CVE-2012-6584Multiple SQL injection vulnerabilities in MYRE Realty Manage…
- CVE-2012-6585Cross-site scripting (XSS) vulnerability in search.php in MY…
Are you affected by CVE-2012-6579?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
