Bug#876462: Fwd: Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-28 Thread Patrick Matthäi
Hello Martin and everyone else, could you help here? Is this the correct commit for CVE-2017-14635? Weitergeleitete Nachricht On Fri, 22 Sep 2017 16:31:00 +0200 Salvatore Bonaccorso wrote: [...] > Unfortunately the patches are not referenced, so must be

Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-24 Thread Markus Koschany
On Fri, 22 Sep 2017 16:31:00 +0200 Salvatore Bonaccorso wrote: [...] > Unfortunately the patches are not referenced, so must be researched in > the repository. I had a look at this issue. I have found

Bug#876462: otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS

2017-09-22 Thread Salvatore Bonaccorso
Source: otrs2 Version: 3.3.9-3 Severity: grave Tags: upstream security Hi, the following vulnerability was published for otrs2. CVE-2017-14635[0]: | In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before | 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage |