Debian LTS: DLA-1119-1: otrs2 security update
Summary
****IMPORTANT UPGRADE NOTES****
==============================
This update requires manual intervention. We strongly recommend to
backup all files and databases before upgrading. If you use the MySQL
backend you should read Debian bug report #707075 and the included
README.Debian file which will provide further information.
If you discover that the maintenance mode is still activated after the
update, we recommend to remove /etc/otrs/maintenance.html and
/var/lib/otrs/httpd/htdocs/maintenance.html which will resolve the issue
.
In addition the following security vulnerabilities were also addressed:
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in OTRS allows remote
attackers to inject arbitrary web script or HTML via a crafted HTML
email
CVE-2014-2553
Cross-site scripting (XSS) vulnerability in OTRS allows remote
authenticated users to inject arbitrary web script or HTML via
vectors related to dynamic fields
CVE-2014-2554
OTRS allows remote attackers to conduct clic...