ALT-BU-2017-3495-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-18350
bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-14635
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Modified: 2024-11-21
CVE-2017-9324
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end.
- DSA-3876
- DSA-3876
- https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.html
- https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.html
- https://www.otrs.com/security-advisory-2017-03-security-update-otrs-versions/
- https://www.otrs.com/security-advisory-2017-03-security-update-otrs-versions/
Closed vulnerabilities
Modified: 2025-02-06
CVE-2017-16651
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html
- 101793
- https://github.com/roundcube/roundcubemail/issues/6026
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3
- [debian-lts-announce] 20171128 [SECURITY] [DLA 1193-1] roundcube security update
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10
- DSA-4030
- http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html
- DSA-4030
- https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10
- [debian-lts-announce] 20171128 [SECURITY] [DLA 1193-1] roundcube security update
- https://github.com/roundcube/roundcubemail/releases/tag/1.3.3
- https://github.com/roundcube/roundcubemail/releases/tag/1.2.7
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.10
- https://github.com/roundcube/roundcubemail/issues/6026
- 101793