{"id":"DEBIAN-CVE-2008-7276","details":"Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to incorrect interpretation of 0700 as a decimal value.","modified":"2026-08-04T06:03:21.004644844Z","published":"2011-03-18T16:55:01.360Z","upstream":["CVE-2008-7276"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2008-7276"}],"affected":[{"package":{"name":"otrs2","ecosystem":"Debian:11","purl":"pkg:deb/debian/otrs2?arch=source&distro=bullseye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.2-1"}]}],"versions":["2.0.4p01-10","2.0.4p01-11","2.0.4p01-12","2.0.4p01-13","2.0.4p01-14","2.0.4p01-14.1","2.0.4p01-15","2.0.4p01-16","2.0.4p01-17","2.0.4p01-18","2.0.4p01-6","2.0.4p01-7","2.0.4p01-8","2.0.4p01-9","2.0.99beta1-1","2.0.99beta1-2","2.1.1-1","2.1.3-1","2.1.4-1","2.1.4-2","2.1.5-1","2.1.5-2","2.1.5-3","2.1.6-1","2.1.7-1","2.1.7-2","2.2.0~beta2-1","2.2.0~beta3-1","2.2.1-1","2.2.2-1","2.2.3-1","2.2.4-1","2.2.5-1","2.2.5-2","2.2.6-1","2.2.7-1","2.2.7-2","2.2.7-2lenny1","2.2.7-2lenny2","2.2.7-2lenny3","2.2.7-3"],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-7276.json"}}],"schema_version":"1.8.0"}