Memory leak in OTRS - CVE-2017-17476

 

Memory leak in OTRS - CVE-2017-17476

Published: December 25, 2017


Vulnerability identifier: #VU9751
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17476
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to hijack web session on the target system.

The weakness exists due to system leaks the session information to external systems. A remote attacker can send a specially prepared email to an OTRS system, obtain session data and take over the agent’s session.

Successful exploitation of the vulnerability may result in privilege escalation.

Affected software

OTRS
Debian Linux
otrs (Alpine package)

How to mitigate CVE-2017-17476

The vulnerability is addressed in the following versions: 4.0.28, 5.0.26, 6.0.3.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins