Accepted request-tracker3.8 3.8.8-7+squeeze1~bpo50+1 (source all)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Tue, 19 Apr 2011 21:30:28 +0200
Source: request-tracker3.8
Binary: request-tracker3.8 rt3.8-clients rt3.8-apache2 rt3.8-db-postgresql rt3.8-db-mysql rt3.8-db-sqlite
Architecture: source all
Version: 3.8.8-7+squeeze1~bpo50+1
Distribution: lenny-backports
Urgency: high
Maintainer: Debian Request Tracker Group <pkg-request-tracker-maintainers@lists.alioth.debian.org>
Changed-By: Jan Wagner <waja@cyconet.org>
Description:
request-tracker3.8 - extensible trouble-ticket tracking system
rt3.8-apache2 - Apache 2 specific files for request-tracker3.8
rt3.8-clients - mail gateway and command-line interface to request-tracker3.8
rt3.8-db-mysql - MySQL database backend for request-tracker3.8
rt3.8-db-postgresql - PostgreSQL database backend for request-tracker3.8
rt3.8-db-sqlite - SQLite database backend for request-tracker3.8
Closes: 614576
Changes:
request-tracker3.8 (3.8.8-7+squeeze1~bpo50+1) lenny-backports; urgency=low
.
* Rebuild for lenny-backports.
.
request-tracker3.8 (3.8.8-7+squeeze1) stable-security; urgency=high
.
* Security fix: fix information leakage in scrips (Closes: 614576;
CVE-2011-1008)
* Multiple security fixes for:
- Remote code execution in external custom fields (CVE-2011-1685)
- Information disclosure via SQL injection (CVE-2011-1686)
- Information disclosure via search interface (CVE-2011-1687)
- Information disclosure via directory traversal (CVE-2011-1688)
- User javascript execution via XSS vulnerability (CVE-2011-1689)
- Authentication credentials theft (CVE-2011-1690)
Checksums-Sha1:
877ee38f7ab14e8672d8b6c676de605c63aeae13 1663 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.dsc
be3ac598dcbf584f9bcd9a49248a9ccd3affb330 5109734 request-tracker3.8_3.8.8.orig.tar.gz
b10608a82571d3fe5931183b911930ff9a736f07 82594 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.diff.gz
f3377019fd07c276c6c28920474fb7bf570d35dd 4657590 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1_all.deb
3c6e48fbaac4760fdcc4ab70544fc389f8724726 48026 rt3.8-clients_3.8.8-7+squeeze1~bpo50+1_all.deb
0c9a33244d88e1818cef0e2c5e137f89872b8770 12518 rt3.8-apache2_3.8.8-7+squeeze1~bpo50+1_all.deb
a60e6d4cf112960f0a91529aad0a674b513dcdc8 11208 rt3.8-db-postgresql_3.8.8-7+squeeze1~bpo50+1_all.deb
cb15baf82aaa286791a03bed668aac1023a82c87 11206 rt3.8-db-mysql_3.8.8-7+squeeze1~bpo50+1_all.deb
687a563000d386f453528b6ee493163ec06933f2 11298 rt3.8-db-sqlite_3.8.8-7+squeeze1~bpo50+1_all.deb
Checksums-Sha256:
2676cbec75a96077e055a4617bba1eedfe91e31def5a502e38573bbf18fbd278 1663 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.dsc
d3932febc5b3fa1da1168713f305a095ea6b40dd22d508849471e6637ba04c02 5109734 request-tracker3.8_3.8.8.orig.tar.gz
91f34e4ed34c4baa57178598c7e5dbe986cee0fbeb78a02f95761c4db7456ad9 82594 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.diff.gz
365df4131ce8d229be8dc0dbd3f8b5d28ebde47bddacc0862b5fa409f62a38e1 4657590 request-tracker3.8_3.8.8-7+squeeze1~bpo50+1_all.deb
3c15664a7dc476de64bfbff8c659677760ae20350496fd1cc4c6026ad18bb00b 48026 rt3.8-clients_3.8.8-7+squeeze1~bpo50+1_all.deb
cd3f44eda6c27e12e8c144ac0746089c8705b4573794d74fae6d045281dc4e41 12518 rt3.8-apache2_3.8.8-7+squeeze1~bpo50+1_all.deb
368f41f21f0ccb2d272ff4255738b0c3655e5b19f1b51d1b5ac25ac09c604e8c 11208 rt3.8-db-postgresql_3.8.8-7+squeeze1~bpo50+1_all.deb
dc247e6e191358643e82be616d0b2b26358a159bed0f3377ef8faec7e333ed3c 11206 rt3.8-db-mysql_3.8.8-7+squeeze1~bpo50+1_all.deb
e75a3ed9a9528693183fe912af5415ae00236bcd8fb2c23ac28f4bb1466f8c43 11298 rt3.8-db-sqlite_3.8.8-7+squeeze1~bpo50+1_all.deb
Files:
eb4685868639b8c01e93334d680a7bc9 1663 misc optional request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.dsc
de062840ce6e2fdb323d77dddf8ff485 5109734 misc optional request-tracker3.8_3.8.8.orig.tar.gz
4f42683b26ccd814ebb1e74e2499d86f 82594 misc optional request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.diff.gz
840276af32c381fe7345be33c15ffa08 4657590 misc optional request-tracker3.8_3.8.8-7+squeeze1~bpo50+1_all.deb
6fcc59804645135973c6bce77d56cba8 48026 misc optional rt3.8-clients_3.8.8-7+squeeze1~bpo50+1_all.deb
8c58f299931267254dd9fbccc64226cc 12518 misc optional rt3.8-apache2_3.8.8-7+squeeze1~bpo50+1_all.deb
cafd04704d89bbfd2528d7a4705a522a 11208 misc optional rt3.8-db-postgresql_3.8.8-7+squeeze1~bpo50+1_all.deb
574ea6fcc47d4f66953100b5ebe122b1 11206 misc optional rt3.8-db-mysql_3.8.8-7+squeeze1~bpo50+1_all.deb
84b91a6ea3608d68e13cd7f7a860ebd4 11298 misc optional rt3.8-db-sqlite_3.8.8-7+squeeze1~bpo50+1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iD8DBQFNreOp9u6Dud+QFyQRAqjbAKCeZ1yGjXyvtkqeUq7J4S7AgkGvegCeLS20
BGRmSRSFOhCN05MdhLo3KtY=
=alD4
-----END PGP SIGNATURE-----
Accepted:
request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.diff.gz
to main/r/request-tracker3.8/request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.diff.gz
request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.dsc
to main/r/request-tracker3.8/request-tracker3.8_3.8.8-7+squeeze1~bpo50+1.dsc
request-tracker3.8_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/request-tracker3.8_3.8.8-7+squeeze1~bpo50+1_all.deb
rt3.8-apache2_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/rt3.8-apache2_3.8.8-7+squeeze1~bpo50+1_all.deb
rt3.8-clients_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/rt3.8-clients_3.8.8-7+squeeze1~bpo50+1_all.deb
rt3.8-db-mysql_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/rt3.8-db-mysql_3.8.8-7+squeeze1~bpo50+1_all.deb
rt3.8-db-postgresql_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/rt3.8-db-postgresql_3.8.8-7+squeeze1~bpo50+1_all.deb
rt3.8-db-sqlite_3.8.8-7+squeeze1~bpo50+1_all.deb
to main/r/request-tracker3.8/rt3.8-db-sqlite_3.8.8-7+squeeze1~bpo50+1_all.deb
Reply to: