Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 177630 - www-apps/otrs Cross-Site Scripting and Cross-Site Request Forgery (CVE-2007-2524)
Summary: www-apps/otrs Cross-Site Scripting and Cross-Site Request Forgery (CVE-2007-2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/25205/
Whiteboard: ~4 [noglsa]
Keywords:
: 172305 183562 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-05-08 13:53 UTC by Lars Hartmann
Modified: 2007-09-12 09:39 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-05-08 13:53:39 UTC
ciri has reported some vulnerabilities in OTRS (Open Ticket Request System), which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

1) Input passed to the "Subaction" parameter in index.pl is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

2) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to perform actions with the privileges of a target user, who is tricked into visiting a malicious website.

The vulnerabilities are reported in version 2.0.4. Other versions may also be affected.

Solution:
Reportedly fixed in version 2.2.0 beta.

Reproducible: Always
Comment 1 Lars Hartmann 2007-05-08 15:23:05 UTC
maintainers - please provide a fix
Comment 2 Elias Probst 2007-05-15 21:24:58 UTC
Does anybody know of a backported patch for 2.0.4/2.1.7?

As 2.1.7 is currently facing some heavy changes (bug#172305) it would be nice having this patch available for 2.0.4 and being able including it in 2.1.7 as soon as I've finished the rewrite of this ebuild.

Regards, Elias P.
Comment 3 Lars Hartmann 2007-05-22 11:27:27 UTC
I looked at theyr bugzilla and it seems that they are still working on a patch for 2.0.4
Comment 4 Lars Hartmann 2007-05-24 08:16:02 UTC
They released a fix:
http://users.otrs.com/~me/otrs-2.0.4-OSA-2007-01-patch.diff

maintainers - please provide an updated ebuild
Comment 5 Lars Hartmann 2007-05-30 16:31:37 UTC
maintainers - please advice
Comment 6 Lars Hartmann 2007-06-07 01:50:31 UTC
maintainers - please advise and patch as necessary
Comment 7 Lars Hartmann 2007-06-19 16:53:32 UTC
maintainers - please advice
Comment 8 Jakub Moc (RETIRED) gentoo-dev 2007-06-28 18:46:10 UTC
*** Bug 183562 has been marked as a duplicate of this bug. ***
Comment 9 Jakub Moc (RETIRED) gentoo-dev 2007-06-28 19:00:39 UTC
*** Bug 172305 has been marked as a duplicate of this bug. ***
Comment 10 Allen Parker 2007-06-28 19:09:37 UTC
Since OTRS 2.0.5 (released 05-29-2007) fixes this, can we perhaps change this to a version bump?
Comment 11 Lars Hartmann 2007-07-04 06:50:53 UTC
maintainers - please advice and bump as necessary
Comment 12 Elias Probst 2007-07-11 15:19:50 UTC
I finally resolved all problems that kept me from closing bug#172305

Expect updated ebuilds for OTRS during next days.

Regards, Elias P.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-19 08:08:21 UTC
there's 2.1.5 in the tree, does it fix this issue?
Comment 14 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-20 14:43:01 UTC
web-apps, please advise.
Comment 15 Gunnar Wrobel (RETIRED) gentoo-dev 2007-09-12 07:02:39 UTC
I added otrs-2.2.2 to the tree now and removed the older, insecure ebuilds.

I currently did not remove the mask since I'd like some feedback whether the ebuild really installs fine.

The post install instructions are somewhat more complex but I had no problem installing it. If I could get one confirmation of this I'd remove the mask.
Comment 16 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-12 09:39:56 UTC
Thanks Gunnar. In any case, I think we can close this one without glsa. feel free to reopen if you disagree.