LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

otrs2: privilege escalation

Package(s):otrs2 CVE #(s):CVE-2013-4088
Created:June 20, 2013 Updated:June 26, 2013
Description:

From the Debian advisory:

It was discovered that users with a valid agent login could use crafted URLs to bypass access control restrictions and read tickets to which they should not have access.

Alerts:
Debian DSA-2712-1 2013-06-19
Mageia MGASA-2013-0196 2013-07-01
Mandriva MDVSA-2013:188 2013-07-02
Debian DSA-2733-1 2013-08-02
openSUSE openSUSE-SU-2013:1338-1 2013-08-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds