Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 499804 (CVE-2014-1471) - <www-apps/otrs-4.0.12: Cross-Site Request Forgery and SQL Injection Vulnerabilities (CVE-2014-{1471,1694})
Summary: <www-apps/otrs-4.0.12: Cross-Site Request Forgery and SQL Injection Vulnerabi...
Status: RESOLVED OBSOLETE
Alias: CVE-2014-1471
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: http://secunia.com/advisories/56655/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-30 16:28 UTC by Agostino Sarubbo
Modified: 2016-03-29 07:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-01-30 16:28:50 UTC
From ${URL} :

Description

Two vulnerabilities have been reported in OTRS, which can be exploited by malicious users to conduct SQL 
injection attacks and by malicious people to conduct cross-site request forgery attacks.

1) The application allows users to perform certain actions via HTTP requests without performing proper 
validity checks to verify the requests. This can be exploited to e.g. create tickets and/or send 
follow-ups to existing tickets when a logged-in user visits a specially crafted web page.

2) Certain unspecified input is not properly sanitised before being used in a SQL query. This can be 
exploited to manipulate SQL queries by injecting arbitrary SQL code.

The vulnerabilities are reported in 3.3.x versions prior to 3.3.4, 3.2.x versions prior to 3.2.14, and 
3.1.x versions prior to 3.1.19.


Solution:
Update to version 3.3.4, 3.2.14, or 3.1.19.

Provided and/or discovered by:
1) Reported by the vendor.
2) The vendor credits Karsten Nielsen, Vasgard GmbH.

Original Advisory:
OSA-2014-01:
https://www.otrs.com/security-advisory-2014-01-csrf-issue-customer-web-interface/

OSA-2014-02:
https://www.otrs.com/security-advisory-2014-02-sql-injection-issue/


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-02-07 22:28:02 UTC
CVE-2014-1694 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1694):
  Multiple cross-site request forgery (CSRF) vulnerabilities in (1)
  CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3)
  CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/
  in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before
  3.2.14, and 3.3.x before 3.3.4 allow remote attackers to hijack the
  authentication of arbitrary users for requests that (5) create tickets or
  (6) send follow-ups to existing tickets.

CVE-2014-1471 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1471):
  SQL injection vulnerability in the StateGetStatesByType function in
  Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before
  3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows remote attackers
  to execute arbitrary SQL commands via vectors related to a ticket search
  URL.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-03-29 07:39:33 UTC
No vulnerable versions left in tree.