Debian Security Advisory
DSA-3502-1 roundup -- security update
- Date Reported:
- 03 Mar 2016
- Affected Packages:
- roundup
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-6276.
- More information:
-
Ralf Schlatterbeck discovered an information leak in roundup, a web-based issue tracking system. An authenticated attacker could use it to see sensitive details about other users, including their hashed password.
After applying the update, which will fix the shipped templates, the site administrator should ensure the instanced versions (in /var/lib/roundup usually) are also updated, either by patching them manually or by recreating them.
More info can be found in the upstream documentation at http://www.roundup-tracker.org/docs/upgrading.html#user-data-visibility
For the oldstable distribution (wheezy), this problem has been fixed in version 1.4.20-1.1+deb7u1.
For the stable distribution (jessie), this problem has been fixed in version 1.4.20-1.1+deb8u1.
For the testing (stretch) and unstable (sid) distribution, this problem has not yet been fixed.
We recommend that you upgrade your roundup packages.