MGASA-2014-0094

    Dashboard / Vulnerabilities / MGASA-2014-0094

    MGASA-2014-0094

    Published: 25 Feb 2014Last Modified: 16 Apr 2026

    Summary: Updated otrs packages fix security vulnerabilities and a missing dependency

    Details: Updated otrs package fixes security vulnerabilities: In OTRS before 3.2.14, an attacker that managed to take over the session of a logged in customer could create tickets and/or send follow-ups to existing tickets due to missing challenge token checks (CVE-2014-1694). In OTRS before 3.2.14, an attacker with a valid customer or agent login could inject SQL in the ticket search URL (CVE-2014-1471). The update also adds a missing dependency which prevented database creation during web based installation.

    Affected packages

    Package

    Name: otrs

    Purl: pkg:rpm/mageia/otrs?arch=source&distro=mageia-3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.2.14-1.mga3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High