Gonzalez Posted May 28, 2007 Report Posted May 28, 2007 -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1- --------------------------------------------------------------------------Debian Security Advisory DSA 1298-1 security (at) debian (dot) org [email concealed]http://www.debian.org/security/ Moritz MuehlenhoffMay 28th, 2007 http://www.debian.org/security/faq- --------------------------------------------------------------------------Package : otrs2Vulnerability : missing input sanitisingProblem-Type : remoteDebian-specific: noCVE ID : CVE-2007-2524It was discovered that the Open Ticket Request System performsinsufficient input sanitising for the Subaction parameter, which allowsthe injection of arbitrary web script code.The oldstable distribution (sarge) doesn't include otrs2.For the stable distribution (etch) this problem has been fixed inversion 2.0.4p01-18.The unstable distribution (sid) isn't affected by this problem.We recommend that you upgrade your otrs2 package.Upgrade Instructions- --------------------wget urlwill fetch the file for youdpkg -i file.debwill install the referenced file.If you are using the apt-get package manager, use the line forsources.list as given below:apt-get updatewill update the internal databaseapt-get upgradewill install corrected packagesYou may use an automated update by adding the resources from thefooter to the proper configuration.Debian GNU/Linux 4.0 alias etch- -------------------------------Source archives:http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.0.4p01-18.dscSize/MD5 checksum: 613 716da567e5255819ce0049c9f83ff3eahttp://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.0.4p01-18.diff.gzSize/MD5 checksum: 17791 bf688dfdc4f48596aa2325d5713ccd9chttp://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.0.4p01.orig.tar.gzSize/MD5 checksum: 1283474 93d2b21bfc8e97568a66ca5cb3f22b91Architecture independent components:http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.0.4p01-18_all.debSize/MD5 checksum: 1154348 83966b5e0dcc373617b3b4e4dc35e28cThese files will probably be moved into the stable distribution onits next update.- ---------------------------------------------------------------------------------For apt-get: deb http://security.debian.org/ stable/updates mainFor dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/mainMailing list: debian-security-announce (at) lists.debian (dot) org [email concealed]Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>-----BEGIN PGP SIGNATURE-----Version: GnuPG v1.4.6 (GNU/Linux)iD8DBQFGWruvXm3vHE4uyloRAt1MAKCV6BnxJ34ZQ5cCL8+ggkiiE1dXZwCfWqVcKVvYS4+qFNJFeert3EZLLFw==CkQf-----END PGP SIGNATURE----- Quote