Package        : otrs2
Version        : 3.3.18-1+deb8u6
CVE ID         : CVE-2018-16586 CVE-2018-16587


Fabien Arnoux discovered several security issues in email validation
of otrs system.

CVE-2018-16586

    Load external image or CSS resources in browser when user opens a
    malicious email.

CVE-2018-16587

    Remote deletions of arbitrary files that the OTRS web server user
    has write access when opening malicious email.

For Debian 8 "Jessie", these problems have been fixed in version
3.3.18-1+deb8u6.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1521-1: otrs2 security update

September 26, 2018
Fabien Arnoux discovered several security issues in email validation of otrs system

Summary

CVE-2018-16586

Load external image or CSS resources in browser when user opens a
malicious email.

CVE-2018-16587

Remote deletions of arbitrary files that the OTRS web server user
has write access when opening malicious email.

For Debian 8 "Jessie", these problems have been fixed in version
3.3.18-1+deb8u6.

We recommend that you upgrade your otrs2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : otrs2
Version : 3.3.18-1+deb8u6
CVE ID : CVE-2018-16586 CVE-2018-16587

Related News