MGASA-2014-0094
Dashboard / Vulnerabilities / MGASA-2014-0094
Summary: Updated otrs packages fix security vulnerabilities and a missing dependency
Details: Updated otrs package fixes security vulnerabilities: In OTRS before 3.2.14, an attacker that managed to take over the session of a logged in customer could create tickets and/or send follow-ups to existing tickets due to missing challenge token checks (CVE-2014-1694). In OTRS before 3.2.14, an attacker with a valid customer or agent login could inject SQL in the ticket search URL (CVE-2014-1471). The update also adds a missing dependency which prevented database creation during web based installation.
References: https://advisories.mageia.org/MGASA-2014-0094.html, http://www.otrs.com/security-advisory-2014-01-csrf-issue-customer-web-interface/, http://www.otrs.com/security-advisory-2014-02-sql-injection-issue/, http://www.otrs.com/release_notes_otrs_help_desk_3_2_14/, https://bugs.mageia.org/show_bug.cgi?id=10669, https://bugs.mageia.org/show_bug.cgi?id=12473
Affected packages
Package
Name: otrs
Purl: pkg:rpm/mageia/otrs?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
