Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 3124-1] otrs2 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 3124-1] otrs2 security update


Chronologisch Thread 
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 3124-1] otrs2 security update
  • Date: Sat, 10 Jan 2015 12:40:49 +0000
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
  • Old-return-path: <carnil AT master.debian.org>
  • Priority: urgent
  • Resent-date: Sat, 10 Jan 2015 12:41:13 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <G3tP21at7ZF.A.nNE.o3RsUB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3124-1 security AT debian.org
http://www.debian.org/security/ Salvatore Bonaccorso
January 10, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : otrs2
CVE ID : CVE-2014-9324

Thorsten Eckel of Znuny GMBH and Remo Staeuble of InfoGuard discovered
a privilege escalation vulnerability in otrs2, the Open Ticket Request
System. An attacker with valid OTRS credentials could access and
manipulate ticket data of other users via the GenericInterface, if a
ticket webservice is configured and not additionally secured.

For the stable distribution (wheezy), this problem has been fixed in
version 3.1.7+dfsg1-8+deb7u5.

For the upcoming stable distribution (jessie), this problem has been
fixed in version 3.3.9-3.

For the unstable distribution (sid), this problem has been fixed in
version 3.3.9-3.

We recommend that you upgrade your otrs2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUsR10AAoJEAVMuPMTQ89EPyQQAIfRWWN3Uhlyfd8le5l1wXYv
t6cIvZZF59dqXVhDqFLKAiEBlQBrjRi86QRdEHSgpJiTX7rVoqK4WoeV921d03b8
Yh5tB4YT8a09aGZzjrfhWKRfETu/RjVmtKw8uaA8j8nn+YPFERS2QaGm4Ss+sXVz
ozQXD7xwpyAVncnH9MAvLb/Vl+8AXC+2xq0JxT+2VhoUIA49X8rYD1TmB08PqzzM
9yVgHMskc4kkImKKffHA4LZPnlb4MFyR2ReGT6QclUf0bDkONW3tj6RFx6pxe1uQ
tpeCBdKkBR83n1qXwN5q1n+ltlrwooeBEEdddSyKMvxe5sZzEE5AHF+Rjpwu9XLd
nriio8My7iUMcU6IRKeJ1GyHxrufhN+z+E6ICwHm5f5q33AsnyFWHFqaCsFr7WQM
KWWhhO/3cl/8fOOlC1+x3aIxbZ/ck5DuV70c4oQMZakYrxM5o0YPbhbe7ryl2p2x
GDiZwpZeJEoKVbyuK8bvQ0IHp3YSPpFuo50JgfpEHY7yFdrmv04EUVhf4h8YMnRw
iMOmJyTdptozH119OCG1UOcAbO7tBXWI7uBzgef5ZEgscnP5cQTmuOUwkDR8EBxC
Tt95GV9Cs7ejuvdyDguGLhEFhQZlSQFRznnr5QaPIMkM1N+C6nh7j4CmGLQ+rmqb
sbcv0+6/qnWtbavdBcXp
=l3FQ
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST AT lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster AT lists.debian.org
Archive: E1Y9vLV-0003OO-2y AT master.debian.org">https://lists.debian.org/E1Y9vLV-0003OO-2y AT master.debian.org




  • [IT-SecNots] [SECURITY] [DSA 3124-1] otrs2 security update, Salvatore Bonaccorso, 10.01.2015

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang