Debian Security Advisory

DLA-3057-1 request-tracker4 -- LTS security update

Date Reported:
23 Jun 2022
Affected Packages:
request-tracker4
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-38562.
More information:

It was discovered that there was an issue in request-tracker4, a extensible ticket/issue tracking system. Sensitive information could have been revealed by way of a timing attack on the authentication system.

  • CVE-2021-38562

    Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.

For Debian 9 Stretch, these problems have been fixed in version 4.4.1-3+deb9u4.

We recommend that you upgrade your request-tracker4 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS