Vulnonym.com

CVE-2011-2084 - Hedgiest Fairies

Description

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history by leveraging access to a privileged account.

Reference

http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.html http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.html http://www.securityfocus.com/bid/53660 http://secunia.com/advisories/49259