Multiple XSS and denial of service vulnerabilitie

Bug #675324 reported by Bas van den Dikkenberg
266
This bug affects 1 person
Affects Status Importance Assigned to Milestone
otrs2 (Ubuntu)
Fix Released
Medium
Unassigned
Lucid
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: otrs

There is a New version of otrs out to fix this isue see http://otrs.org/releases/2.4.8/

CVE References

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

visibility: private → public
affects: otrs (Ubuntu) → otrs2 (Ubuntu)
Changed in otrs2 (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This was fixed in 2.4.8+dfsg1-1 in Ubuntu 11.04.

Changed in otrs2 (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Bas van den Dikkenberg (bas-dikkenberg) wrote :

When wil there be a fix for 10.04 becouse thats where we reporte the bug not voor 11.04

so it would be nice if you fixed also for 10.04

Changed in otrs2 (Ubuntu):
status: Fix Released → In Progress
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Bas, as mentioned in comment #1, otrs2 is community maintained and not officially supported so an update will not be made by the security team. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures.

Changed in otrs2 (Ubuntu):
status: In Progress → Fix Released
Changed in otrs2 (Ubuntu Lucid):
status: New → Triaged
Revision history for this message
Bas van den Dikkenberg (bas-dikkenberg) wrote :

i am not a programmer, but as far is see its te same fix only it also need to be released 10.04

Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in otrs2 (Ubuntu Lucid):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.