CVE-2014-1474: Bestpractical Rt
Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.
Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address.
Affected products
- Bestpractical Rt: version 4.2.0 only; version 4.2.1 only; version 4.2.2 only
- Email::address::list Project Email::address::list: up to and including 0.01
Published 2014-07-15. Last modified 2026-06-17.