[SECURITY] [DSA 3124-1] otrs2 security update

From: Salvatore Bonaccorso <carnil@debian.org>
To: bugtraq@securityfocus.com
Cc:
Subject: [SECURITY] [DSA 3124-1] otrs2 security update
Date:


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3124-1                   security@debian.org
http://www.debian.org/security/                      Salvatore Bonaccorso
January 10, 2015                       http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : otrs2
CVE ID         : CVE-2014-9324

Thorsten Eckel of Znuny GMBH and Remo Staeuble of InfoGuard discovered
a privilege escalation vulnerability in otrs2, the Open Ticket Request
System. An attacker with valid OTRS credentials could access and
manipulate ticket data of other users via the GenericInterface, if a
ticket webservice is configured and not additionally secured.

For the stable distribution (wheezy), this problem has been fixed in
version 3.1.7+dfsg1-8+deb7u5.

For the upcoming stable distribution (jessie), this problem has been
fixed in version 3.3.9-3.

For the unstable distribution (sid), this problem has been fixed in
version 3.3.9-3.

We recommend that you upgrade your otrs2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUsR10AAoJEAVMuPMTQ89EPyQQAIfRWWN3Uhlyfd8le5l1wXYv
t6cIvZZF59dqXVhDqFLKAiEBlQBrjRi86QRdEHSgpJiTX7rVoqK4WoeV921d03b8
Yh5tB4YT8a09aGZzjrfhWKRfETu/RjVmtKw8uaA8j8nn+YPFERS2QaGm4Ss+sXVz
ozQXD7xwpyAVncnH9MAvLb/Vl+8AXC+2xq0JxT+2VhoUIA49X8rYD1TmB08PqzzM
9yVgHMskc4kkImKKffHA4LZPnlb4MFyR2ReGT6QclUf0bDkONW3tj6RFx6pxe1uQ
tpeCBdKkBR83n1qXwN5q1n+ltlrwooeBEEdddSyKMvxe5sZzEE5AHF+Rjpwu9XLd
nriio8My7iUMcU6IRKeJ1GyHxrufhN+z+E6ICwHm5f5q33AsnyFWHFqaCsFr7WQM
KWWhhO/3cl/8fOOlC1+x3aIxbZ/ck5DuV70c4oQMZakYrxM5o0YPbhbe7ryl2p2x
GDiZwpZeJEoKVbyuK8bvQ0IHp3YSPpFuo50JgfpEHY7yFdrmv04EUVhf4h8YMnRw
iMOmJyTdptozH119OCG1UOcAbO7tBXWI7uBzgef5ZEgscnP5cQTmuOUwkDR8EBxC
Tt95GV9Cs7ejuvdyDguGLhEFhQZlSQFRznnr5QaPIMkM1N+C6nh7j4CmGLQ+rmqb
sbcv0+6/qnWtbavdBcXp
=l3FQ
-----END PGP SIGNATURE-----





Copyright © 1995-2019 LinuxRocket.net. All rights reserved.