MGASA-2012-0322
Date: | November 6th, 2012 |
Affected releases: | 2 |
Description:
Updated otrs package fixes security vulnerabilities:
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request
System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and
3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6,
and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web
script or HTML via an e-mail message body with (1) a Cascading Style
Sheets (CSS) expression property in the STYLE attribute of an arbitrary
element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element
(CVE-2012-2582).
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x
before 3.1.10, when Firefox or Opera is used, allows remote attackers
to inject arbitrary web script or HTML via an e-mail message body with
nested HTML tags (CVE-2012-4600).
Cross-site scripting (XSS) vulnerability in Open Ticket Request System
(OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x
before 3.1.11 allows remote attackers to inject arbitrary web script
or HTML via an e-mail message body with whitespace before a javascript:
URL in the SRC attribute of an element, as demonstrated by an IFRAME
element (CVE-2012-4751).
Updated Packages:
otrs-3.1.11-1.mga2
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2582
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4600
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4751
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-01/
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-02/
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-03/
http://lists.opensuse.org/opensuse-updates/2012-09/msg00079.html
https://bugs.mageia.org/show_bug.cgi?id=7527