Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian Wheezy DSA-2712-1 Critical: OTRS2 Access Control Bypass

debian
Calendar Grey June 19, 2013
Debian Logo
A critical security advisory warns of a high-risk privilege escalation vulnerability in OTRS2 affecting Debian's stable release. Prompt action is essential.
It was discovered that users with a valid agent login could use crafted URLs to bypass access control restrictions and read tickets to which they should not have access

Summary

It was discovered that users with a valid agent login could use
crafted URLs to bypass access control restrictions and read tickets to
which they should not have access.

The oldstable distribution (squeeze) is not affected by this problem.

For the stable distribution (wheezy), this problem has been fixed in
version 3.1.7+dfsg1-8+deb7u2.

For the unstable distribution (sid), this problem has been fixed in
version 3.2.8-1.

We recommend that you upgrade your otrs2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: otrs2
CVE ID: CVE-2013-4088

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here