Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:2632-1

Опубликовано: 02 окт. 2017
Источник: suse-cvrf

Описание

Security update for otrs

This update for otrs to version 3.3.18 fixes the following issue:

This security issue was fixed:

  • CVE-2017-14635: Remote authenticated users could have leveraged statistics-write permissions to gain privileges via code injection (bsc#1059691).

Список пакетов

openSUSE Leap 42.2
otrs-3.3.18-9.1
otrs-doc-3.3.18-9.1
otrs-itsm-3.3.14-9.1
openSUSE Leap 42.3
otrs-3.3.18-9.1
otrs-doc-3.3.18-9.1
otrs-itsm-3.3.14-9.1

Описание

In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.


Затронутые продукты
openSUSE Leap 42.2:otrs-3.3.18-9.1
openSUSE Leap 42.2:otrs-doc-3.3.18-9.1
openSUSE Leap 42.2:otrs-itsm-3.3.14-9.1
openSUSE Leap 42.3:otrs-3.3.18-9.1

Ссылки