|
|
Subscribe / Log in / New account

Debian alert DLA-2053-1 (otrs2)

From:  Abhijith PA <abhijith@disroot.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2053-1] otrs2 security update
Date:  Wed, 1 Jan 2020 08:30:15 +0530
Message-ID:  <174b025b-a945-90b5-1bc7-3327b4dc89a6@disroot.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : otrs2 Version : 3.3.18-1+deb8u12 CVE ID : CVE-2019-18179 Debian Bug : 945251 An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, which are in the queue where attacker doesn’t have permissions. For Debian 8 "Jessie", this problem has been fixed in version 3.3.18-1+deb8u12. We recommend that you upgrade your otrs2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl4MCzoACgkQhj1N8u2c KO/d+Q/9E+JjGi6zliozs3v3VP9BmMYt9aXhEVKPEuBArAEFBc60OxH9awW4FQ4N m4cQ0UkbkCs8wZyEFI5eyRJW1jwdep8N+nMzqdxwYZLCw+kelBo/s9Va/n8ePdc/ 2t7As1bAm5/RoFXstSfI/Yb3S+j2pDi9fnU9lAW+zyB1ffJ9SeJgH4IFgvylv53p X+WIXz4ZIPrndmnm/SNiA9Nz5oFweTn2KmIwaN9l01qlVaBkpldEFnejCB2iKUwb 1taglLOtJGc34EMfk2vJ5CVyiyZlX2ux5+ct1eUcz6NKdchGLh2W/X5GCpNs65Cu xsVJCvlEnY37BHG1JSBPPLFiuJd7Xn9Op5NukdFSZEMen4FrAVTO7vbrs8jdyTCm 8QcItzLjPBPbAr8m0Un/OXf+iOakLV+nDTf6u8jbb9HYxJ/I407NGjUQZf+NdHzM z4t25Kn+ljxdPWU2MguLI4+kXUgu1zhSmpnb0vymAlcV5BTT55DOVd9kwnd91pZz dzahioZKTQEhzNHTg8NWHHot4kemr9G7Pdox2qxwXiMqnH0XP3cPr2+bGa8jRXTY DDacIAJS7sD/0q8Udl6z8ExCwyqcTwE/9AhPzdCmfYx9qoTSs2aw4M8rZ9uUjNzq 0ZthPNMwPIXDnZFr0RoJvI89Ro12aLJZwPddCSuBrgLw7FsZUHI= =XUWY -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds