DSA-2536-1 otrs2 -- cross-site scripting

Related Vulnerabilities: CVE-2012-2582   CVE-2012-4600  

It was discovered that Open Ticket Request System (OTRS), a ticket request system, contains a cross-site scripting vulnerability when email messages are viewed using Internet Explorer. This update also improves the HTML security filter to detect tag nesting. For the stable distribution (squeeze), this problem has been fixed in version 2.4.9+dfsg1-3+squeeze3. For the unstable distribution (sid), this problem has been fixed in version 3.1.7+dfsg1-5. We recommend that you upgrade your otrs2 packages.

Debian Security Advisory

DSA-2536-1 otrs2 -- cross-site scripting

Date Reported:
30 Aug 2012
Affected Packages:
otrs2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-2582, CVE-2012-4600.
More information:

It was discovered that Open Ticket Request System (OTRS), a ticket request system, contains a cross-site scripting vulnerability when email messages are viewed using Internet Explorer. This update also improves the HTML security filter to detect tag nesting.

For the stable distribution (squeeze), this problem has been fixed in version 2.4.9+dfsg1-3+squeeze3.

For the unstable distribution (sid), this problem has been fixed in version 3.1.7+dfsg1-5.

We recommend that you upgrade your otrs2 packages.