|
|
Subscribe / Log in / New account

Debian alert DLA-1473-1 (otrs2)

From:  Markus Koschany <apo@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1473-1] otrs2 security update
Date:  Tue, 21 Aug 2018 15:54:50 +0200
Message-ID:  <ea476e60-1061-b0ed-b5e4-18579214b960@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : otrs2 Version : 3.3.18-1+deb8u5 CVE ID : CVE-2018-14593 Francesco Sirocco discovered a privilege escalation flaw in otrs2, the Open Ticket Request System. An attacker who is logged into OTRS as a user may escalate their privileges by accessing a specially crafted URL. For Debian 8 "Jessie", this problem has been fixed in version 3.3.18-1+deb8u5. We recommend that you upgrade your otrs2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlt8GalfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeR1nQ//Zhjr8U0l/swl0M1PSBhgnCOrYLgOpTdPeOhupKZgUpH+HVCBpDbF3uJF fcWJZmIJMB+X7DGcQaSnkEp6joSkrLOCTRaKmkFY8VjJPrDmPuBDeTPkVfbssjTD gr4Qm0+Kmbjtw5WsUNrhW5W6mH2iaKyyWjwk1/DzN/Fu5ySKe0JhYN2Jv9qVFbBf QLsleTNfbXmNRz4jFfPp+89pFcZ8KgZaVibjICaCjqF45n8YXv+yip++yEY8QCyK v8J2q0OIXG+4HoFHf9CvHfT9AN+T9ezHh5EHRkUURUeq6cjfSX1S4Q/IwaQk2NrM HRt/mKJGovcINeyITE9ujduXjL6AyD0mPm6be+iAA/KM5pF5wkoHzXEDWUhEHAdB EC0REKryXegeNlcnmwTu4RHQjCbTyEBV0pbzGX06UeThTLwjEDUfY/MvyiMWto3D /+IxZQh+ziUZ52Z0N0K9yUZhceMehHWI2KCcFw3uqZEPfL1TONM+thjaJdiXkWdf JYZ3nJjx3+FXblEq0EHJ7VruNrTfLDtnYH1J39RQ6dHh3jMyYfexcLiKTXLVNhEv 7a0sccXrtPIKee+HVznxGiv/hP8ye4R2JW1VcsBNT/n3fzLtZdtUW1U9pQ91dwB2 VTft7jcBCR+4idGycEhPap5JaLPJb1GAOXifKMpOXK0btomV3iU= =UL66 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds