Oval Definition:oval:com.ubuntu.precise:def:20141694000
Revision Date:2014-02-04Version:1
Title:CVE-2014-1694 on Ubuntu 12.04 LTS (precise) - medium.
Description:Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/ in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allow remote attackers to hijack the authentication of arbitrary users for requests that (5) create tickets or (6) send follow-ups to existing tickets.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-1694
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'otrs2' package in precise is affected and needs fixing.
  • BACK