SB2018100405 - OpenSUSE Linux update for otrs
Published: October 4, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2018-14593)
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access control restrictions when accessing certain URL. A remote authenticated attacker with agent privileges can escalate privileges and gain access to otherwise restricted functionality.
2) Input validation error (CVE-ID: CVE-2018-16586)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image or CSS resources.
3) Input validation error (CVE-ID: CVE-2018-16587)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.
Remediation
Install update from vendor's website.