Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecurityNotifies] [announce] OTRS Security Advisory 2010-02: OTRS 2.4.8 (Aitutaki Beach)

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecurityNotifies] [announce] OTRS Security Advisory 2010-02: OTRS 2.4.8 (Aitutaki Beach)


Chronologisch Thread 
  • From: Hauke Böttcher <hauke.boettcher AT otrs.com>
  • To: announce AT otrs.org
  • Subject: [IT-SecurityNotifies] [announce] OTRS Security Advisory 2010-02: OTRS 2.4.8 (Aitutaki Beach)
  • Date: Wed, 15 Sep 2010 14:32:26 +0200
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>

Dear Community Members,

++++++++++ OTRS Security Advisory 2010-01 OTRS 2.4.8 ++++++++++


Release:            OTRS 2.4.8
Status:             stable
Code Name:          Aitutaki Beach


SECURITY FIXES:
===============

---------------------------------------------------------------
 OTRS Security Advisory 2010-02            <security AT otrs.org>
---------------------------------------------------------------
 ID:         OSA-2010-02
 Date:       2010-09-15
 Title:      Multiple XSS and denial of service vulnerabilities
 Severity:   Less critical
 Product:    OTRS 2.4.x, OTRS 2.3.x
 Fixed in:   OTRS 2.4.8, OTRS 2.3.6
 CVE:        CVE-2010-2080
---------------------------------------------------------------

To read the entire Security Advisory please follow this link:

ENGLISH VERSION:


GERMAN VERSION:



ENHANCEMENTS:
============

* Updated Czech translation, thanks to O2BS.com, s r.o. 
  Jakub Hanus!
* Updated Portuguese Brazilian translation file, thanks to 
  Fabricio Luiz Machado!
* Updated Ukrainian language translation, thanks to 
  Belskii Artem!
* Updated Danish translation, thanks to Jesper Rønnov, 
  Faaborg-Midtfyn Kommune!


BUG FIXES:
==========


* Bug# 4658 - Can't delete attachment from AdminAttachment 
              interface.
              [ http://bugs.otrs.org/show_bug.cgi?id=4658 ]

* Bug# 4889 - Inline images from Lotus Notes were not displayed 
              in the ticket zoom.
              [ http://bugs.otrs.org/show_bug.cgi?id=4889 ]

* Bug# 4977 - mod_perl was not used on Fedora when using RPM.
              [ http://bugs.otrs.org/show_bug.cgi?id=4977 ]

* Bug# 4967 - Object method "new" could not be located by package
              error when using Perl 5.10.1.
              [ http://bugs.otrs.org/show_bug.cgi?id=4967 ]

* Bug# 5094 - Bulk pending date/time was not applied to tickets.
              [ http://bugs.otrs.org/show_bug.cgi?id=5094 ]

* Bug# 5164 - Pending time was not working if agent was located
              in a different timezone.
              [ http://bugs.otrs.org/show_bug.cgi?id=5164 ]

* Bug# 4786 - AgentTicketCompose ONLY: when assigning a next 
              state and adding an attachment, the next state was
              reseted until the next screen refresh.
              [ http://bugs.otrs.org/show_bug.cgi?id=4786 ]

* Bug# 4999 - Cache for customer user was not refreshed when a
              preference was updated.
              [ http://bugs.otrs.org/show_bug.cgi?id=4999 ]

* Bug# 5242 - New lines were not displayed in HTML notification
              mails on Lotus Notes.
              [ http://bugs.otrs.org/show_bug.cgi?id=5242 ]

* Bug# 5210 - LinkQuote generated high CPU load when processing 
              a large volume of data.
              [ http://bugs.otrs.org/show_bug.cgi?id=5210 ]

* Bug# 5742 - Outgoing email link detection was not working 
              properly.
              [ http://bugs.otrs.org/show_bug.cgi?id=5742 ]

* Bug# 5132 - New owner validation always asked to set an owner.
              [ http://bugs.otrs.org/show_bug.cgi?id=5132 ]

MD5 CHECKSUMS:
==============

70baf24a67c5f248080ad50f0c19d77f
9b1f7f877c0d74d9fe70ea2f47c941a6
f1202fb4b7f1ed9a368bd16502ceb905
629affdf142889f9055d21bbd72016a8
6691148e8d0a165b34f2a78688aa4069
cbc48ae51c9f5942e076f600b6358898
86e6e4016dffc6110e7d2f179fdfb0ec
c68005e52d4cd0321eb3078b370c58a0
37e88ff3588f9205a40b62c279c6f737
fddab03c46c3705c89b4355f12abb0ac
83ce39fbc681f65e1704d464c0423e02
d3ae78a94659431a17c26ef8de55ec19
a0272ac3b3602d1af4f78b259968c87e

SOFTWARE DOWNLOAD: 
===================

Please note that we have relaunched our website www.otrs.com.
The software can now be downloaded exclusively  


A complete list of all download mirrors (ftp/http/rsync) is 
available at http://otrs.org/download/

YOUR CONTRIBUTION:
===================

* Please send information regarding vulnerabilities in OTRS to

* We kindly ask for your assistance to update the translation 
  files! The current status can be found here: 


FEEDBACK & BUG REPORTING: 
========================= 
Although OTRS 2.4.8 has been tested before, we appreciate
your contributions. As always, you’re encouraged to tell 
us what you think, using this feedback e-Mail: [enjoy at otrs.com
or by filing a bug in Bugzilla [http://bugs.otrs.org].

--


Hauke Jan Böttcher
Director Marketing

OTRS AG
Norsk-Data-Straße 1
61352 Bad Homburg
Germany

T: +49 (0) 6172 681988 0
F: +49 (0) 9421 56818 18
I:  http://www.otrs.com/

Business Location: Bad Homburg
Country Court: Bad Homburg, HRB 10751
VAT ID: DE256610065
Chairman: Burchard Steinbild
Managing Board: André Mindermann (CEO)
---------------------------------------------------------------------
OTRS mailing list: announce - Webpage: http://otrs.org/
Archive: http://lists.otrs.org/pipermail/announce
To unsubscribe: http://lists.otrs.org/cgi-bin/listinfo/announce
---------------------------------------------------------------------
OTRS mailing list: announce - Webpage: http://otrs.org/
Archive: http://lists.otrs.org/pipermail/announce
To unsubscribe: http://lists.otrs.org/cgi-bin/listinfo/announce

  • [IT-SecurityNotifies] [announce] OTRS Security Advisory 2010-02: OTRS 2.4.8 (Aitutaki Beach), Hauke Böttcher, 15.09.2010

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang