RT 3.8.10 Released - Security Release
Kevin Falcone <[email protected]> Thu, 14 Apr 2011 10:00:54 -0400
| Newsgroups | gmane.comp.bug-tracking.request-tracker.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============0149363565== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="liOOAslEiF7prFVr" Content-Disposition: inline --liOOAslEiF7prFVr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline This release of RT contains important bugfixes. You can download it from: http://download.bestpractical.com/pub/rt/release/rt-3.8.10.tar.gz http://download.bestpractical.com/pub/rt/release/rt-3.8.10.tar.gz.sig SHA1 sums 98678a4ce4dbdfb13ceeeb88236d49bd0f5562c7 rt-3.8.10.tar.gz 8e228df450d0cdc255e3db725b5bdf302771c75d rt-3.8.10.tar.gz.sig This release, in addition to being a bugfix release, also resolves a number of security vulnerabilities. It resolves CVE-2011-1685, CVE-2011-1686, CVE-2011-1687, CVE-2011-1688, CVE-2011-1689, and CVE-2011-1690. * Cleanups identified by perlcritic. * Clear the system attribute cache to avoid 'sticky' attributes like the queue subject tag. * Fix our signature escaping so we better match FCKEditor and don't misidentify signatures during processing. * Add the ability to create BasedOn Custom Fields from intiialdata * Provide a callback to affect the display format in admin pages * Fix id prefixing on Custom Fields to be RTIR compatible * Fix #16656 - Requestors with OwnTicket could show up in the owner list in other Queues. * Don't attach the original multipart mail to notifications that already contain one part of it. * Work around CGI.pm 3.51 and 3.52 which add ; charse=ISO-8859-1 to our utf-8 encoded javascript. --liOOAslEiF7prFVr Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (Darwin) iEYEARECAAYFAk2m/hAACgkQ0+gKWp5CJQo2LACbBT20lhc4XgmGwycpwxhVm0v1 L4sAnjd813thyJ3GJ3k4INFxz5kGtm7n =Ik4E -----END PGP SIGNATURE----- --liOOAslEiF7prFVr-- --===============0149363565== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ RT-Announce mailing list [email protected] http://lists.bestpractical.com/cgi-bin/mailman/listinfo/rt-announce --===============0149363565==--