[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1212-1] otrs2 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : otrs2
Version        : 3.3.18-1~deb7u2
CVE ID         : CVE-2017-15864 CVE-2017-16664 CVE-2017-16854 CVE-2017-16921

Four vulnerabilities were discovered in the Open Ticket Request System
which could result in information disclosure or the execution of arbitrary
shell commands by logged-in agents.

For Debian 7 "Wheezy", these problems have been fixed in version
3.3.18-1~deb7u2.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlo5eZQACgkQnUbEiOQ2
gwKdyg//ffljPMW0ad3rkBxkZnsoLFd5aFvrJBtlJuh0YbCUpRAOooevPDrWJg8W
4j1613nt6G+crlUuiCfKcEDpnBDURMVzhhv5ob+9UPleEC712MVR5+f5u8InKh48
Hj48jd+1vSO+4jDuXKYsUpO9L/Ini/GipQT2MTav0T6Oha57jdgqvJ1tumMfJwfF
SwGobDYiN4K6+I1FxRKDEzqmPplxmBWZcmWMu2/RRuiFYRTFCLZhy3UVXXAOCzWa
B7qibTQ0avgYmNHAvpCpnQlTVs7ZJaQgCU+XaDOcc4gMziVEfmqZlNjJGvBLEZ7l
BiTAk+Omj+w+MelR6r9wqXnUa+oGGJswciwiui9/A+7+/xJxxh4XNtLMIXIkkrOg
byNai994Mq2DzsvncX0v3FpA0xmuj6sgGYzbV+8GWozQJm5o52DSyjPYBbC+ULMu
084e/el/8QNt9iPY+YvlZNJT377WtApp6v+MJTbgi7mOaHu8jTVu5v4DXoN3mf+K
WQMJe5rDYN8y9otdALNmyYdf9aPfvJi1c3OFsrgpjM4QjlT584alLOrzD39qzpKe
+2BPuARcpnwYJK7av77+o/JJYKjQ3Rx5e3oXrDfWd7wtZuq7KYWIQN2DRf5l/gIp
kH8AnPRmcGxNSYvLPM5aI1+XICWrkC5OAXqSzLHxvf8oslJjaXE=
=z+ft
-----END PGP SIGNATURE-----


Reply to: