Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8 LTS: DLA-2198-1 Moderate: OTRS2 Information Disclosure Risk

debian lts
Calendar Grey May 1, 2020
Dist Debian Esm H88
Enhance otrs2 Application on Debian Jessie to resolve vulnerabilities related to sensitive information leakage and token tampering risks.
Several vulnerabilities have been discovered in otrs2 (Open source Ticket Request System)

Summary

CVE-2020-1770

Support bundle generated files could contain sensitive information
that might be unwanted to be disclosed.

CVE-2020-1772

It’s possible to craft Lost Password requests with wildcards in the
Token value, which allows attacker to retrieve valid Token(s),
generated by users which already requested new passwords.

CVE-2020-1774

When user downloads PGP or S/MIME keys/certificates, exported file
has same name for private and public keys. Therefore it’s possible
to mix them and to send private key to the third-party instead of
public key.

For Debian 8 "Jessie", these problems have been fixed in version
3.3.18-1+deb8u15.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: otrs2
Version: 3.3.18-1+deb8u15
CVE ID: CVE-2020-1770 CVE-2020-1772 CVE-2020-1774

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here