exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 5181-1

Debian Security Advisory 5181-1
Posted Jul 28, 2022
Authored by Debian | Site debian.org

Debian Linux Security Advisory 5181-1 - Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2022-25802
SHA-256 | 10cb7d285e0a4e3b4ada46863427434e156f617d414617b3d3d30c3e57e315e9

Debian Security Advisory 5181-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5181-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 13, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : request-tracker4
CVE ID : CVE-2022-25802

Multiple vulnerabilities have been discovered in Request Tracker, an
extensible trouble-ticket tracking system.

CVE-2022-25802

It was discovered that Request Tracker is vulnerable to a cross-site
scripting (XSS) attack when displaying attachment content with
fraudulent content types.

Additionally it was discovered that Request Tracker did not perform full
rights checks on accesses to file or image type custom fields, possibly
allowing access to these custom fields by users without rights to access
to the associated objects, resulting in information disclosure.

For the oldstable distribution (buster), these problems have been fixed
in version 4.4.3-2+deb10u2.

For the stable distribution (bullseye), these problems have been fixed in
version 4.4.4+dfsg-2+deb11u2.

We recommend that you upgrade your request-tracker4 packages.

For the detailed security status of request-tracker4 please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/request-tracker4

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmLPHf5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QZFBAAhYVb+ndyJufLPBj1NchSSHIO4TTQ0PCzXLR3WIXILhiQYwaII0rSqKmQ
5KuybJ5R+JQLrCASq3r/xAn0tW9rEgBInHyJQY1XqqCQSIvokJqG73PzdCahuH38
WBFN3k8+yT/C+wYPt+zQOTfAW5zDZ0r63XuC9gcrUGPcCXHP+V1H2dD5glxN9d1z
Hv1gysXuGZ3OLT3gLhRDpJBYmA7gLxEIONadLoofbBqSk8SCm9acWnwx+GOwBnbY
9vrVN57+nWDgBq/POdFC07iIIfQRGHf1BamfS/zhxZVun9R1TyiG7tO/BuHD89rM
J8A7f/V9j9f5wlBtFqjqA8XuJdOx5Pusp4bfOconrhKomUKgNE0dhYtMR9oGZuQC
WgUWbbvn+9Zsjken7hx2O6Grx/ZAg0K5zoDd/HQYhgJfLMBZ6FSUU4NMW25EWdU+
SOw1RVAMe60ZV78OidmJyZQ/xXO13D/LFEnFk3Q2tT3T5pHa70qBIyg9QLDyiJrz
YOGltAffdmhQXic6Aj9geBLMMnEkpLfPnehUN8tQkh3oYLUOqCJ9ztOUcHJyZCjE
JxICk/2JMjGmbzzWoZmAcnfZzwsq4ZmvB+fey8IJLRTok1Li+Cqh0Omm6FbV8kfN
wVfZv3cffnwPtpueYIn08nk0C1fZCEyNVWEsL6u9+m3f4pTYSVQ=
=98sY
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close