security advisorydebiancross-site scripting
Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5911-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 30, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker4 CVE ID : CVE-2024-3262 CVE-2025-2545 CVE-2025-30087 Debian Bug : 1068452 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. For the stable distribution (bookworm), these problems have been fixed in version 4.4.6+dfsg-1.1+deb12u2. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent flaws in the Request Tracker have resulted in potential data leaks and Cross-Site Scripting vulnerabilities. It is imperative to update your systems without delay to ensure security.. Request Tracker, Debian Security, Information Disclosure, Cross-Site Scripting, Vulnerability Management. . LinuxSecurity.com Team
Apr 30, 2025
Debian