Debian Security Advisory
DLA-3057-1 request-tracker4 -- LTS security update
- Date Reported:
- 23 Jun 2022
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-38562.
- More information:
It was discovered that there was an issue in request-tracker4, a extensible ticket/issue tracking system. Sensitive information could have been revealed by way of a timing attack on the authentication system.
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
For Debian 9
Stretch, these problems have been fixed in version 4.4.1-3+deb9u4.
We recommend that you upgrade your request-tracker4 packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS