CVE-2010-4765

OTRS < 2.4.8 - Authenticated Race Condition in FileWrite Method

Title source: llm
STIX 2.1

Description

Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic circumstances by creating tickets.

References (2)

Core 2
Core References
Patch x_refsource_confirm
http://bugs.otrs.org/show_bug.cgi?id=4936

Scores

EPSS 0.0062
EPSS Percentile 45.0%

Details

CWE
CWE-362
Status published
Products (29)
otrs/otrs 0.5 beta1 (8 CPE variants)
otrs/otrs 1.0 rc1 (3 CPE variants)
otrs/otrs 1.0.0
otrs/otrs 1.0.1
otrs/otrs 1.0.2
otrs/otrs 1.1 rc1
otrs/otrs 1.1.0 rc1 (2 CPE variants)
otrs/otrs 1.1.1
otrs/otrs 1.1.2
otrs/otrs 1.1.3
... and 19 more
Published Mar 18, 2011
Tracked Since Feb 18, 2026