Bug 15024 - otrs new security issue CVE-2014-9324
Summary: otrs new security issue CVE-2014-9324
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/629236/
Whiteboard: has_procedure advisory MGA4-32-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-01-12 19:14 CET by David Walser
Modified: 2015-01-20 15:58 CET (History)
3 users (show)

See Also:
Source RPM: otrs-3.2.16-1.mga4.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2015-01-12 19:14:16 CET
Debian has issued an advisory on January 10:
https://www.debian.org/security/2015/dsa-3124

The issue is fixed upstream in 3.2.17:
https://www.otrs.com/release-notes-otrs-help-desk-3-2-17/
https://www.otrs.com/security-advisory-2014-06-incomplete-access-control/

Updated package uploaded for Mageia 4.

Advisory:
========================

Updated otrs package fixes security vulnerability:

An attacker with valid OTRS credentials could access and manipulate ticket
data of other users via the GenericInterface, if a ticket webservice is
configured and not additionally secured (CVE-2014-9324).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9324
https://www.otrs.com/security-advisory-2014-06-incomplete-access-control/
https://www.otrs.com/release-notes-otrs-help-desk-3-2-17/
https://www.debian.org/security/2015/dsa-3124
========================

Updated packages in core/updates_testing:
========================
otrs-3.2.17-1.mga4

from otrs-3.2.17-1.mga4.src.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 David Walser 2015-01-12 19:14:33 CET
Testing procedure in:
https://bugs.mageia.org/show_bug.cgi?id=12473

Whiteboard: (none) => has_procedure

Comment 2 olivier charles 2015-01-13 19:20:30 CET
Testing on Mageia 4x32 real hardware following procedure mentionned in Comment 1

From current package :
--------------------
otrs-3.2.16-1

Went to :
http://localhost/otrs/installer.pl

Setup mysql database through otrs installer and connected to it.

To updated to testing package :
--------------------------
otrs-3.2.17-1.mga4

Connected back to previous database :
http://127.0.0.1/otrs/index.pl

OK

To check updated testing package could create otrs database from scratch
# urpme otrs
With phpmyadmin, dropped otrs database and
# rm -R -f /var/www/otrs/

Reinstalled otrs-3.2.17-1.mga4 and restarted hhtpd service
Retraced installation

All OK

CC: (none) => olchal

olivier charles 2015-01-13 19:21:35 CET

Whiteboard: has_procedure => has_procedure MGA4-32-OK

Comment 3 William Kenney 2015-01-19 17:03:39 CET
In VirtualBox, M4, KDE, 64-bit

Install mariadb
create mariadb database
In root terminal: systemctl start mysqld.service
Set password to: testotrs
[root@localhost wilcal]# mysqladmin -u root password
type password "testotrs" twice

Package(s) under test:
otrs

default install of otrs

[root@localhost wilcal]# urpmi otrs
Package otrs-3.2.16-1.mga4.noarch is already installed

Stumbling around a bit.....
Installed default otrs, successfully opened:

http://localhost/otrs/installer.pl

followed the steps to set up the database and user, interacted
with otrs using:

http://localhost/otrs/index.pl

install otrs from updates_testing

[root@localhost wilcal]# urpmi otrs
Package otrs-3.2.17-1.mga4.noarch is already installed

Interacted with updated otrs using:

http://localhost/otrs/index.pl

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64

CC: (none) => wilcal.int

Comment 4 William Kenney 2015-01-19 17:04:28 CET
I went about this somewhat differently

In VirtualBox, M4, KDE, 64-bit New install

Install mariadb
create mariadb database
In root terminal: systemctl start mysqld.service
Set password to: testotrs
[root@localhost wilcal]# mysqladmin -u root password
type password "testotrs" twice

Package(s) under test:
otrs

enable updates_testing repos
default install of otrs

[root@localhost wilcal]# urpmi otrs
Package otrs-3.2.17-1.mga4.noarch is already installed

Getting better at it:
Installed default otrs, successfully opened:

http://localhost/otrs/installer.pl

followed the steps to set up the database and user, interacted
with otrs using:

http://localhost/otrs/index.pl

Test platform:
Intel Core i7-2600K Sandy Bridge 3.4GHz
GIGABYTE GA-Z68X-UD3-B3 LGA 1155 MoBo
GIGABYTE GV-N440D3-1GI Nvidia GeForce GT 440 (Fermi) 1GB
RTL8111/8168B PCI Express 1Gbit Ethernet
DRAM 16GB (4 x 4GB)
Mageia 4 64-bit, Nvidia driver
virtualbox-4.3.10-1.1.mga4.x86_64
virtualbox-guest-additions-4.3.10-1.1.mga4.x86_64
William Kenney 2015-01-19 17:04:45 CET

Whiteboard: has_procedure MGA4-32-OK => has_procedure MGA4-32-OK MGA4-64-OK

Comment 5 William Kenney 2015-01-19 17:06:49 CET
For me this update works fine as best I can test it.
Testing complete for mga4 32-bit & 64-bit
I'll validate the update in 24-hours unless oliver or clair does so sooner.
Comment 6 claire robinson 2015-01-19 23:03:28 CET
Validating. Advisory uploaded.

Please push to 4 updates

Thanks

CC: (none) => sysadmin-bugs
Whiteboard: has_procedure MGA4-32-OK MGA4-64-OK => has_procedure advisory MGA4-32-OK MGA4-64-OK
Keywords: (none) => validated_update

Comment 7 Mageia Robot 2015-01-20 15:58:06 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0031.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.