CVE

Id
37395  
CVE No.
CVE-2008-7278  
Status
Candidate  
Description
The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.  
Phase
Assigned (20110318)  
Votes
None (candidate not yet proposed)  
Comments