Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian Jessie: DSA-3876-1 Critical OTRS2 Privilege Escalation Fix

debian
Calendar Grey June 9, 2017
Debian Logo
Debian security patch for OTRS2 mitigates privilege escalation threats caused by inadequate validation within SecureMode settings.
Joerg-Thomas Vogt discovered that the SecureMode was insufficiently validated in the OTRS ticket system, which could allow agents to escalate their privileges

Summary

Joerg-Thomas Vogt discovered that the SecureMode was insufficiently
validated in the OTRS ticket system, which could allow agents to
escalate their privileges.

For the stable distribution (jessie), this problem has been fixed in
version 3.3.9-3+deb8u1.

For the upcoming stable distribution (stretch), this problem will be
fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 5.0.20-1.

We recommend that you upgrade your otrs2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: otrs2
CVE ID: CVE-2017-9324

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here