RT 3.0.0 and above, if running on Perl 5.14.0 or higher,
	    are vulnerable to a remote denial-of-service via the email
	    gateway; any installation which accepts mail from untrusted
	    sources is vulnerable, regardless of the permissions
	    configuration inside RT. This denial-of-service may
	    encompass both CPU and disk usage, depending on RT's logging
	    configuration. This vulnerability is assigned
	    CVE-2014-9472.
	  RT 3.8.8 and above are vulnerable to an information
	    disclosure attack which may reveal RSS feeds URLs, and thus
	    ticket data; this vulnerability is assigned
	    CVE-2015-1165. RSS feed URLs can also be leveraged to
	    perform session hijacking, allowing a user with the URL to
	    log in as the user that created the feed; this vulnerability
	    is assigned CVE-2015-1464.