Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2671-1 Moderate: Request Tracker Multiple Security Issues

debian
Calendar Grey May 22, 2013
Debian Logo
Various vulnerabilities in the Request Tracker system could result in unauthorized changes to data and possible exploitation. Immediate action needed.
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system

Summary

CVE-2012-4733

A user with the ModifyTicket right can bypass the DeleteTicket right
or any custom lifecycle transition rights and thus modify ticket data
without authorization.

CVE-2013-3368

The rt command line tool uses semi-predictable temporary files. A
malicious user can use this flaw to overwrite files with permissions
of the user running the rt command line tool.

CVE-2013-3369

A malicious user who is allowed to see administration pages can run
arbitrary mason components (without control of arguments), which may
have negative side-effects.

CVE-2013-3370

Request Tracker allows direct requests to private callback
components, which could be used to exploit a Request Tracker
extension or a local callback which uses the arguments passed to it
insecurely.

CVE-2013-3371

Request Tracker is vulnerable to cross-site scripting attacks via
attachment filenames.

CVE-2013-3372

Dominic Hargreaves discovered that Request Tracker is vulnerable to
an ...

Read the Full Advisory

Package: request-tracker4
CVE ID: CVE-2012-4733 CVE-2013-3368 CVE-2013-3369 CVE-2013-3370

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here