Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
172

Ubuntu 22.04 LTS: Request Tracker Multiple Issues Advisory USN-7692-1

Several security issues were fixed in Request Tracker.. ========================================================================== Ubuntu Security Notice USN-7692-1 August 13, 2025 request-tracker5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Request Tracker. Software Description: - request-tracker5: An open source, enterprise-grade issue and ticket tracking system. Details: It was discovered that Request Tracker was susceptible to timing attacks. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2021-38562) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious attachments were supplied. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-25802) It was discovered that Request Tracker would incorrectly redirect users in certain instances. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-25803) Tom Wolters discovered that Request Tracker could leak information when malicious email headers were supplied. An attacker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-41259, CVE-2023-41260) It was discovered that Request Tracker could leak information through its transaction search. An attacker with access to the transaction query builder of Request Tracker could possibly use this issue to access sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-45024) It was discovered that Request Tracker erroneously stored ticket information in a web browser's cache. An attacker with direct access to a system could possibly use this issue to accesssensitive information. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-3262) It was discovered that Request Tracker made use of an obsolete cryptographic algorithm for emails sent with S/MIME encryption. An attacker could possibly use this issue to access sensitive information. (CVE-2025-2545) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious parameters were included in a search URL. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-30087) It was discovered that Request Tracker was susceptible to cross-site scripting attacks when malicious permalinks or assets were provided. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-31500, CVE-2025-31501) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 request-tracker5 5.0.7+dfsg-2ubuntu0.1 rt5-fcgi 5.0.7+dfsg-2ubuntu0.1 rt5-standalone 5.0.7+dfsg-2ubuntu0.1 Ubuntu 24.04 LTS request-tracker5 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro rt5-fcgi 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro rt5-standalone 5.0.5+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS request-tracker5 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro rt5-fcgi 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro rt5-standalone 5.0.1+dfsg-1ubuntu1+esm1 Available with Ubuntu Pro After a standard system update you need to restart Request Tracker to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7692-1 CVE-2021-38562, CVE-2022-25802,CVE-2022-25803, CVE-2023-41259, CVE-2023-41260, CVE-2023-45024, CVE-2024-3262, CVE-2025-2545, CVE-2025-30087, CVE-2025-31500, CVE-2025-31501 Package Information: https://launchpad.net/ubuntu/+source/request-tracker5/5.0.7+dfsg-2ubuntu0.1 . Various vulnerabilities addressed in Request Tracker impact Long Term Support versions of Ubuntu, resulting in possible exposure of confidential information.. Request Tracker, Ubuntu security advisory, denial of service, cross-site scripting, Ubuntu LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 14, 2025 Critical Ubuntu
197

Debian Bullseye: DLA-4157-1 Moderate: Request Tracker Info Disclosure

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4157-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Santiago Ruano Rincón May 08, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : request-tracker4 Version : 4.4.4+dfsg-2+deb11u4 CVE ID : CVE-2024-3262 CVE-2025-2545 CVE-2025-30087 Debian Bug : 1068452 1104424 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. For Debian 11 bullseye, these problems have been fixed in version 4.4.4+dfsg-2+deb11u4. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several security flaws identified in Issue Tracker might result in data leakage, cross-site scripting (XSS) issues, and inadequate encryption vulnerabilities.. Request Tracker Security, Debian LTS Advisories, XSS Risks, Weak Encryption Threats. . LinuxSecurity.com Team

Calendar%202 May 08, 2025 Debian LTS
87

Debian: DSA-5911-1 moderate: request tracker information disclosure

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5911-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 30, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker4 CVE ID : CVE-2024-3262 CVE-2025-2545 CVE-2025-30087 Debian Bug : 1068452 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. For the stable distribution (bookworm), these problems have been fixed in version 4.4.6+dfsg-1.1+deb12u2. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent flaws in the Request Tracker have resulted in potential data leaks and Cross-Site Scripting vulnerabilities. It is imperative to update your systems without delay to ensure security.. Request Tracker, Debian Security, Information Disclosure, Cross-Site Scripting, Vulnerability Management. . LinuxSecurity.com Team

Calendar%202 Apr 30, 2025 Debian
87

Debian: DSA-5909-1 moderate: request tracker cross-site scripting

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5909-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 30, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker5 CVE ID : CVE-2024-3262 CVE-2025-2545 CVE-2025-30087 CVE-2025-31500 CVE-2025-31501 Debian Bug : 1068453 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. For the stable distribution (bookworm), these problems have been fixed in version 5.0.3+dfsg-3~deb12u3. We recommend that you upgrade your request-tracker5 packages. For the detailed security status of request-tracker5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Identify multiple security weaknesses in Request Tracker leading to data exposure, XSS threats, and encryption issues. Prompt for enhancements suggested!. Request Tracker vulnerabilities, Debian advisory, security updates, encryption issues. . LinuxSecurity.com Team

Calendar%202 Apr 30, 2025 Debian
87

Debian DSA-5909-1 moderate: request tracker information disclosure

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5909-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 30, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker5 CVE ID : CVE-2024-3262 CVE-2025-2545 CVE-2025-30087 CVE-2025-31500 CVE-2025-31501 Debian Bug : 1068453 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in information disclosure, cross-site scripting and use of weak encryption for S/MIME emails. For the stable distribution (bookworm), these problems have been fixed in version 5.0.3+dfsg-3~deb12u3. We recommend that you upgrade your request-tracker5 packages. For the detailed security status of request-tracker5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover significant vulnerabilities in Request Tracker that impact various editions and find out how to fortify your Debian setup.. Request Tracker, Debian Security, information disclosure, scripting fix, weak encryption. . LinuxSecurity.com Team

Calendar%202 Apr 30, 2025 Debian
172

Ubuntu 23.10: USN-6529-1 moderate: request tracker remote access

Several security issues were fixed in Request Tracker.. ========================================================================== Ubuntu Security Notice USN-6529-1 December 04, 2023 request-tracker4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Request Tracker. Software Description: - request-tracker4: An enterprise-grade issue tracking system Details: It was discovered that Request Tracker incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-38562, CVE-2022-25802, CVE-2023-41259, CVE-2023-41260) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: request-tracker4 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-clients 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.10.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.23.10.1 Ubuntu 23.04: request-tracker4 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-clients 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.04.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.23.04.1 Ubuntu 22.04 LTS: request-tracker4 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-apache2 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-clients 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-mysql 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-fcgi 4.4.4+dfsg-2ubuntu1.22.04.1 rt4-standalone 4.4.4+dfsg-2ubuntu1.22.04.1 Ubuntu 20.04 LTS: request-tracker4 4.4.3-2+deb10u3build0.20.04.1 rt4-apache2 4.4.3-2+deb10u3build0.20.04.1 rt4-clients 4.4.3-2+deb10u3build0.20.04.1 rt4-db-mysql 4.4.3-2+deb10u3build0.20.04.1 rt4-db-postgresql 4.4.3-2+deb10u3build0.20.04.1 rt4-db-sqlite 4.4.3-2+deb10u3build0.20.04.1 rt4-fcgi 4.4.3-2+deb10u3build0.20.04.1 rt4-standalone 4.4.3-2+deb10u3build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): request-tracker4 4.4.2-2ubuntu0.1~esm1 rt4-apache2 4.4.2-2ubuntu0.1~esm1 rt4-clients 4.4.2-2ubuntu0.1~esm1 rt4-db-mysql 4.4.2-2ubuntu0.1~esm1 rt4-db-postgresql 4.4.2-2ubuntu0.1~esm1 rt4-db-sqlite 4.4.2-2ubuntu0.1~esm1 rt4-fcgi 4.4.2-2ubuntu0.1~esm1 rt4-standalone 4.4.2-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6529-1 CVE-2021-38562, CVE-2022-25802, CVE-2023-41259, CVE-2023-41260 Package Information: https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.10.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.04.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.22.04.1 https://launchpad.net/ubuntu/+source/request-tracker4/4.4.3-2+deb10u3build0.20.04.1 . Ubuntu Security Notice USN-6529-1 December 04, 2023 request-tracker4 vulnerabilities A security issu. security, request, tracker, =============================================. . LinuxSecurity.com Team

Calendar%202 Dec 04, 2023 Ubuntu
197

Debian DLA-3642-1 Moderate: Request Tracker Email Leak Advisory

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3642-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Salvatore Bonaccorso October 31, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : request-tracker4 Version : 4.4.3-2+deb10u3 CVE ID : CVE-2023-41259 CVE-2023-41260 Debian Bug : 1054516 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 Tom Wolters reported that Request Tracker is vulnerable to accepting unvalidated RT email headers in incoming email and the mail-gateway REST interface. CVE-2023-41260 Tom Wolters reported that Request Tracker is vulnerable to information leakage via response messages returned from requests sent via the mail-gateway REST interface. For Debian 10 buster, these problems have been fixed in version 4.4.3-2+deb10u3. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian Long Term Support team has issued an advisory addressing multiple vulnerabilities in Request Tracker, focusing on email processing and data security.. Debian Security, Request Tracker, Email Vulnerability. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Debian LTS
87

Debian: DSA-5542-1 Moderate: Request Tracker Email Header Issues

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5542-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 30, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : request-tracker4 CVE ID : CVE-2023-41259 CVE-2023-41260 Debian Bug : 1054516 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 Tom Wolters reported that Request Tracker is vulnerable to accepting unvalidated RT email headers in incoming email and the mail-gateway REST interface. CVE-2023-41260 Tom Wolters reported that Request Tracker is vulnerable to information leakage via response messages returned from requests sent via the mail-gateway REST interface. For the oldstable distribution (bullseye), these problems have been fixed in version 4.4.4+dfsg-2+deb11u3. For the stable distribution (bookworm), these problems have been fixed in version 4.4.6+dfsg-1.1+deb12u1. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several security flaws in Request Tracker were revealed, comprising data exposure and unchecked email header inputs.. Debian DSA, Request Tracker, Security Advisory, Information Leakage. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2023 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200