CVE-2008-7277
Publication date 18 March 2011
Last updated 24 July 2024
Ubuntu priority
Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.
Status
Package | Ubuntu Release | Status |
---|---|---|
otrs2 | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic |
Not affected
|
|
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Not in release |