<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>22947</bug_id>
          
          <creation_ts>2010-02-11 20:25:17 +0300</creation_ts>
          <short_desc>CVE-2010-0438: Vulnerability in OTRS-Core allows SQL-Injection</short_desc>
          <delta_ts>2010-02-21 22:32:37 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>otrs</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://otrs.org/advisory/OSA-2010-01-en/</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Dmitry V. Levin">ldv</reporter>
          <assigned_to name="Sergey Y. Afonin">asy</assigned_to>
          <cc>asy</cc>
    
    <cc>pavel.zilke</cc>
    
    <cc>zidex</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>106630</commentid>
    <comment_count>0</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2010-02-11 20:25:17 +0300</bug_when>
    <thetext>Missing security quoting for SQL statements allows agents and customers
to manipulate SQL queries. So it&apos;s possible for authenticated users to
inject SQL queries via string manipulation of statements.

A malicious user may be able to manipulate SQL queries to read or modify
records in the database. This way it could also be possible to get access
to more permissions (e. g. administrator permissions).

To use this vulnerability the malicious user needs to have a valid
Agent-or Customer-session.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106979</commentid>
    <comment_count>1</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-02-21 22:32:37 +0300</bug_when>
    <thetext>otrs-2.4.7-alt1 -&gt; sisyphus:

* Sun Feb 21 2010 Pavel Zilke &lt;zidex at altlinux&gt; 2.4.7-alt1

- Security fixes:
  + Vulnerability in OTRS-Core allows SQL-Injection; CVE-2010-0438 (ALT #22947)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>