Name | CVE-2017-16921 |
Description | In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1212-1, DSA-4066-1 |
Debian Bugs | 883774 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
otrs2 (PTS) | jessie, jessie (lts) | 3.3.18-1+deb8u15 | fixed |
stretch/non-free (security), stretch/non-free (lts), stretch/non-free | 5.0.16-1+deb9u6 | fixed | |
buster/non-free (security), buster/non-free | 6.0.16-2+deb10u1 | fixed | |
bullseye/non-free | 6.0.32-6 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
otrs2 | source | wheezy | 3.3.18-1~deb7u2 | DLA-1212-1 | ||
otrs2 | source | jessie | 3.3.18-1+deb8u3 | DSA-4066-1 | ||
otrs2 | source | stretch | 5.0.16-1+deb9u4 | DSA-4066-1 | ||
otrs2 | source | (unstable) | 6.0.2-1 | 883774 |
https://www.otrs.com/security-advisory-2017-09-security-update-otrs-framework/
https://bugs.otrs.org/show_bug.cgi?id=13357
OTRS-6: https://github.com/OTRS/otrs/commit/d12797bf1efa6722c2ba9af6d8238446c2903cd1
OTRS-5: https://github.com/OTRS/otrs/commit/d433518d7bd8e9e079af67ef9ea7079cd2f59646
OTRS-4: https://github.com/OTRS/otrs/commit/368bc37f137e6344f4db014ee2e03c38e2fc62d2
OTRS-4: https://github.com/OTRS/otrs/commit/4043ebb2580cd8f87e7758e95bf0d77eea5c82ae