Updated otrs packages fix security vulnerabilities and a missing dependency
Publication date: 25 Feb 2014Modification date: 25 Feb 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-1694 , CVE-2014-1471
Description
Updated otrs package fixes security vulnerabilities: In OTRS before 3.2.14, an attacker that managed to take over the session of a logged in customer could create tickets and/or send follow-ups to existing tickets due to missing challenge token checks (CVE-2014-1694). In OTRS before 3.2.14, an attacker with a valid customer or agent login could inject SQL in the ticket search URL (CVE-2014-1471). The update also adds a missing dependency which prevented database creation during web based installation.
References
- http://www.otrs.com/security-advisory-2014-01-csrf-issue-customer-web-interface/
- http://www.otrs.com/security-advisory-2014-02-sql-injection-issue/
- http://www.otrs.com/release_notes_otrs_help_desk_3_2_14/
- https://bugs.mageia.org/show_bug.cgi?id=10669
- https://bugs.mageia.org/show_bug.cgi?id=12473
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1694
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1471
SRPMS
4/core
- otrs-3.2.14-1.mga4
3/core
- otrs-3.2.14-1.mga3