[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Accepted otrs2 3.3.18-1+deb8u9 (source all) into oldstable



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 03 May 2019 10:37:13 +0200
Source: otrs2
Binary: otrs2 otrs
Architecture: source all
Version: 3.3.18-1+deb8u9
Distribution: jessie-security
Urgency: high
Maintainer: Patrick Matthäi <pmatthaei@debian.org>
Changed-By: Markus Koschany <apo@debian.org>
Description:
 otrs       - Open Ticket Request System (OTRS 3)
 otrs2      - Open Ticket Request System
Changes:
 otrs2 (3.3.18-1+deb8u9) jessie-security; urgency=high
 .
   * Non-maintainer upload by the LTS team.
   * Fix CVE-2019-9892:
     An attacker who is logged into OTRS as an agent user with appropriate
     permissions may try to import carefully crafted Report Statistics XML that
     will result in reading of arbitrary files of OTRS filesystem.
Checksums-Sha1:
 a87fcb7e5c64647e9bdef8ce63458c4062867c34 1971 otrs2_3.3.18-1+deb8u9.dsc
 2b07d4252865dcc789b08be3ab158433e65e507e 49120 otrs2_3.3.18-1+deb8u9.debian.tar.xz
 57ef579f038d15985c0c03fff01648db0dad70e5 5683504 otrs2_3.3.18-1+deb8u9_all.deb
 b4f98aee726be08f875705d33e53e9d02224bde1 189862 otrs_3.3.18-1+deb8u9_all.deb
Checksums-Sha256:
 8e0f4496a963d3f871cbb2d8103307d10c84f8364c3d85da2af633e9f08a27cf 1971 otrs2_3.3.18-1+deb8u9.dsc
 19b4b0f25a62166ef9394786c9c0fe314ca69d8998d55e96d3c03b64a2d7eab8 49120 otrs2_3.3.18-1+deb8u9.debian.tar.xz
 bcb4b9c884b39992f99184a899d342c7ca58ffa209c3461c5907f0b08d3c9b07 5683504 otrs2_3.3.18-1+deb8u9_all.deb
 ed7c325536df0f5ff4286ec6c2347f092ecaedf14fbe3de524299a54bb7c8840 189862 otrs_3.3.18-1+deb8u9_all.deb
Files:
 7be9c667e92a672edadc59678ee6a9cc 1971 web optional otrs2_3.3.18-1+deb8u9.dsc
 7b4fc48a156f614ff7bbb00757da839c 49120 web optional otrs2_3.3.18-1+deb8u9.debian.tar.xz
 ed7d658bc63a8f279790f3864fd83e80 5683504 web optional otrs2_3.3.18-1+deb8u9_all.deb
 4dd730b67997b206ccff36f4ec920167 189862 web optional otrs_3.3.18-1+deb8u9_all.deb

-----BEGIN PGP SIGNATURE-----

iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlzMBOBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp
YW4ub3JnAAoJENmtFLlRO1HkvjcP/jccIggki0YlB9560D8TaEeZ0MC4gh4BCC2X
No9A2TI/tsfAw6FKRFjkZG8Fo2UZb1PepNPIfXect1XtuFHy0szSLgDcbNvNJgxy
hHHr964+kH4Ofgf+kJbgdGA0PQPtMpUUnQz7q6JyHVck1CS4DvnEE569McVKT7n2
IcNm2bgBGjrZ//bbf4cf07okiGaepWfb5y0xeQISnsihI5+JDnHJkHFBlST048EU
JZsR4+bfXdFaZ1PjHk2bok1vTMH4vbzPtl7A0TohSwMNR47RG5tUM+gIYeww9hib
5QNqE5jKIm7lofeuNR2TEtBowMfL8hsqTJAFowP2z94M3+ud6TqTdlv6ogxTeMuk
V1PI//2khphSi/ZzA3HJo9cg0LXJ9Mar8CAXvlnaEYMHB71w/wYm1fCrqloe4g9H
igqJAEdlRkg83QsuyKEdOcVHiKUO8oD/QiEm7nOXbUFTeCOXQaR2P2OQ3gmw+WBL
7enT3vlTpOtegcNq2ljRIjhfAcInbXa1ey1Nuy9Ymhe0u2dTl/r5ls4G/+TIXdaV
mLKGJW+ZGT/0JYk9Q7rlG+qnCiRY6nUDybijabG99CeTtxQ7/Qv6kRSJksoirY20
C/chu8PVE6BGzFhjhHlajHZrg9Er7LeTtV49prJiyS4isjCAEh3rz/Du5sOCXS2w
6x/wQWb5
=SV4X
-----END PGP SIGNATURE-----


Reply to: