Vulnerability Bulletins

DSA-4069 otrs2 - security update

   
Affected software Debian
 
Francesco Sirocco discovered a flaw in otrs2, the Open Ticket RequestSystem, which could result in session information disclosure when cookiesupport is disabled. A remote attacker can take advantage of this flawto take over an agents session if the agent is tricked into clicking alink in a specially crafted mail.

More info:

https://www.debian.org/security/2017/dsa-4069