Description
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
Problem types
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Product status
Any version before 5.0.8
Credits
Ángel González Berdasco
References
docs.bestpractical.com/release-notes/rt/4.4.8
docs.bestpractical.com/release-notes/rt/5.0.8
lists.debian.org/debian-lts-announce/2025/05/msg00009.html
www.incibe.es/...-recommended-request-tracker-best-practical