SB2011031802 - Multiple vulnerabilities in OTRS



SB2011031802 - Multiple vulnerabilities in OTRS

Published: March 18, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011031802
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2008-7276)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to incorrect interpretation of 0700 as a decimal value.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2008-7277)

The vulnerability allows a remote #AU# to read and manipulate data.

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.


Remediation

Install update from vendor's website.