[DSA 6327-1] request-tracker4 security update
Salvatore Bonaccorso <[email protected]> Sun, 07 Jun 2026 19:25:04 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6327-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso June 07, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker4 CVE ID : CVE-2026-6841 CVE-2026-41073 CVE-2026-41075 CVE-2026-41076 CVE-2026-44229 CVE-2026-44231 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result privilege escalation, information disclosure, SQL injections, LDAP authentication bypass, cross-site scripting or spreadsheet (CSV/formula) injection. For the oldstable distribution (bookworm), these problems have been fixed in version 4.4.6+dfsg-1.1+deb12u4. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/request-tracker4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmolxWJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0TuOhAAnGDI9d4Qf2cZwbo0p8UTANijmIx8Ui/6S3DqEZIuOWYwdf6MHQQfqXRL 954qJn20egidCVftLSgVgpPu3FwbHY/Kc4vpmsbT0eh5I6zjoI/eiuUi6v4J1XzU hcxbTfB7UuhlM+ngovKaCzZmx+S+g/Z6f2tsaCABSjQubQNvWwgX4cSw5qvkLXed VRCixzeWiEz+SW1gykiLP7BEoCuRNPurDbY9JSBpcTgPtrb+SjuZnLhGbRUY2ELL 8sW1gD52RZ8ZTIaeCoFeVQG14/Hj+Ab6HxA15AI8Dk7y9M+6X5aEK470mjCVMJ8/ uk/NuEe6SSEbP+2osyqvIYOOBB9WrYV9jx+JaLI2nk94aAMwELrnPY1bdZ9u1uR/ vEU2Bced9EAhuhtTXhz0bdZG80uryUkc/HDFYzs3sbYFa66Qd6xGXEEw5U18Flat v7GL786zTw5RKdBYdbJ1xieudl4cLb/adLrXhaxnD7JNOibOqfdN167hLpzSUjxV XiZ68osJbkljMvuuwaxeegMHpgxTu4Kx3BXjQvB7pxLg6ZkXrh5/AWfwepF6rvlF U9A8CDreFFbLpPhrPODpWtUaY+wnovlFspj5EItRI/oON/uerwitxkf9lGEF4cL1 T3bCfrEF87RCouYObtlyh1RR9z426ilJgKsOjsaqyxj8rf/oXhc= =loji -----END PGP SIGNATURE-----