-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : otrs2 Version : 3.3.18-1+deb8u8 CVE ID : CVE-2019-9752
It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling. For Debian 8 "Jessie", this problem has been fixed in version 3.3.18-1+deb8u8. We recommend that you upgrade your otrs2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAlyQntcACgkQhj1N8u2c KO88UA/+L5mzF5kIt4OrZPtPBSX3SCmvFochjBHK6nOXM2Hm0tA7vxbqJUxcW8bn ckkZtuqLFE3RKEK6C+LLSQX4n9YqSUDEbcwUinBr7PuD+uGPVfzgjke8f0ud/IpJ +yGM3w6codYjM+oYy+sQJ6uCjDYds9z0cKcmPXMzY3FohzVoMiH4ng/YAmHN9A1D EpyWFMzyjRc7e4ldlKi1I5H5FKx4YwK/Fq10QeHH1LLLPVcqg6PbqYtxzAxF/WqZ uRxM8dbiywAtvuHIew1yySfftwtCJDovvsy4eEzGdYN/hkgpVlp7HbyitnEaXHgr OzPo3iV0NlrtKRoLkL71ewm4WRC+XH/W+8XE4ECd+rSR2DJ8tipcbhbRZU056QLI 4lt6RjK6X3PaxyBfEidZ+vBrDuhJbIouI4lf0ACMbKsyx052vc5QkpFtJ5vZstrZ fUZfMqn0S0RmAJEEX/W65kZB3mZiv9I8x+SEZqqwi5Ko+LfxRy7NseTGlRAjbkGG EUM0MmLOgDJ0ZbpZVGQ6RyRDhtD613cLUUw7lSVD1tE/lQYAwfaQ6XQ7CQ91iU0s Vs8ZgfBPU6YVChrgRZX4xL6pBcuFjQ7falf+MwnyVeUt7oDsG5IvGyMnoMx4qMVU sE6SklhS6nVWYZNE1vEBqWjQzfMgSFooMy3fi/jVAyhWPkXSchE= =gzax -----END PGP SIGNATURE-----
