LWN.net Logo

otrs2: code injection

Package(s):otrs2 CVE #(s):CVE-2007-2524
Created:May 30, 2007 Updated:June 8, 2007
Description: The otrs2 ticket request system fails to properly sanitize input data, allowing the injection of arbitrary code.
Alerts:
Debian DSA-1298-1 2007-05-28

(Log in to post comments)

otrs2: code injection

Posted Jun 14, 2007 20:39 UTC (Thu) by bollin (subscriber, #5582) [Link]

Debian DSA-1299-1 2007-06-07 does not cover OTRS.

Cheers,
Torsten

otrs2: code injection

Posted Jun 14, 2007 21:02 UTC (Thu) by ris (editor, #5) [Link]

The question is, what is the correct CVE number for Debian DSA-1299-1 ? The one given matches the OTRS vulnerability.

otrs2: code injection

Posted Jun 15, 2007 2:42 UTC (Fri) by jake (editor, #205) [Link]

> Debian DSA-1299-1 2007-06-07 does not cover OTRS.

fixed. the original announcement had the wrong CVE, it should be CVE-2007-1841 which is the vulnerability DSA-1299-1 is attached to now

jake

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds