Debian Security Advisory
DSA-2536-1 otrs2 -- cross-site scripting
- Date Reported:
- 30 Aug 2012
- Affected Packages:
- otrs2
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-2582, CVE-2012-4600.
- More information:
-
It was discovered that Open Ticket Request System (OTRS), a ticket request system, contains a cross-site scripting vulnerability when email messages are viewed using Internet Explorer. This update also improves the HTML security filter to detect tag nesting.
For the stable distribution (squeeze), this problem has been fixed in version 2.4.9+dfsg1-3+squeeze3.
For the unstable distribution (sid), this problem has been fixed in version 3.1.7+dfsg1-5.
We recommend that you upgrade your otrs2 packages.