Updated otrs package fixes security vulnerabilities
Publication date: 01 Jul 2013Modification date: 01 Jul 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-3551 , CVE-2013-4088
Description
An attacker with a valid agent login could manipulate URLs in the ticket watch mechanism to see contents of tickets they are not permitted to see (CVE-2013-3551, CVE-2013-4088).
References
- https://bugs.mageia.org/show_bug.cgi?id=10352
- http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2013-03/
- http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2013-04/
- http://www.debian.org/security/2013/dsa-2696
- http://www.debian.org/security/2013/dsa-2712
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3551
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4088
SRPMS
3/core
- otrs-3.2.8-1.mga3
2/core
- otrs-3.2.8-1.mga2