~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
Candidate: CVE-2012-2582
PublicDate: 2012-08-23
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2582
 http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-01/
 http://www.kb.cert.org/vuls/id/582879
Description:
 Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request
 System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x
 before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and
 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script
 or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS)
 expression property in the STYLE attribute of an arbitrary element or (2)
 UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element.
Ubuntu-Description:
Notes:
Bugs:
Priority: low
Discovered-by:
Assigned-to:

Patches_otrs2:
upstream_otrs2: released (3.1.9)
hardy_otrs2: ignored (reached end-of-life)
lucid_otrs2: ignored (reached end-of-life)
natty_otrs2: released (2.4.9+dfsg1-3+squeeze3build0.11.04.1)
oneiric_otrs2: ignored (reached end-of-life)
precise_otrs2: ignored (reached end-of-life)
precise/esm_otrs2: DNE (precise was needed)
quantal_otrs2: not-affected (3.1.7+dfsg1-4)
raring_otrs2: not-affected (3.1.7+dfsg1-4)
saucy_otrs2: not-affected (3.1.7+dfsg1-4)
trusty_otrs2: not-affected (3.1.7+dfsg1-4)
utopic_otrs2: not-affected (3.1.7+dfsg1-4)
vivid_otrs2: not-affected (3.1.7+dfsg1-4)
vivid/stable-phone-overlay_otrs2: DNE
vivid/ubuntu-core_otrs2: DNE
wily_otrs2: not-affected (3.1.7+dfsg1-4)
xenial_otrs2: not-affected (3.1.7+dfsg1-4)
yakkety_otrs2: not-affected (3.1.7+dfsg1-4)
zesty_otrs2: not-affected (3.1.7+dfsg1-4)
devel_otrs2: not-affected (3.1.7+dfsg1-4)