Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 532912 (CVE-2014-9324) - <www-apps/otrs-4.0.12: Incomplete Access Control (CVE-2014-9324)8
Summary: <www-apps/otrs-4.0.12: Incomplete Access Control (CVE-2014-9324)8
Status: RESOLVED FIXED
Alias: CVE-2014-9324
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://www.otrs.com/security-advisor...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-18 09:45 UTC by Agostino Sarubbo
Modified: 2015-10-05 12:31 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-12-18 09:45:48 UTC
From ${URL} :

Security Advisory Details

ID: OSA-2014-06
Date: 2014-12-16
Title: Incomplete Access Control
Severity: low (Overall CVSS Score : 2.7)
Product: OTRS 3.2.x, 3.3.x, 4.0.x
Fixed in: OTRS 3.2.17, 3.3.11, 4.0.3
URL: [TBD]
FULL CVSS v2 VECTOR: (AV:N/AC:M/AU:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C/CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND)
References: CVE-2014-9324


@maintainer(s): since the package or the affected version has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-12-28 23:53:20 UTC
CVE-2014-9324 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9324):
  The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before
  3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access
  and modify arbitrary tickets via unspecified vectors.
Comment 2 Ian Delaney (RETIRED) gentoo-dev 2015-10-05 08:07:31 UTC
Author: Ian Delaney <idella4@gentoo.org>
Date:   Thu Oct 1 12:55:13 2015 +0800

    www-apps/otrs: Designate new maintainer in metadata, bump to -4.0.12
    
    New maintainer added & supported under the proxy-maintainers herd, testing
    and revision carried out thanks also to wraeth, fix to broken .png file
    applied according to past bug #466190 supplied by Blackb|rd, all patches and
    revisons of ebuilds supplied via bug cited below, releases after -3.2.12
    skipped, holding off from beta versions of version 5.x for now, removed old
    versions prior to -3.2.12. Finally closes the gentoo bug.

commit 8719c0549974cef1a8f1d7b3362f1be35678b478
Author: Ian Delaney <idella4@gentoo.org>
Date:   Mon Oct 5 16:04:44 2015 +0800

    www-apps/otrs clean old version wrt bug #532912