LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Advisory Watch: June 14th, 2013
Linux Security Week: June 4th, 2013
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Debian: 2220-1: request-tracker3.6, request-tracker3.8: Multiple vulnerabilities Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Debian Several vulnerabilities were in Request Tracker, an issue tracking system. CVE-2011-1685 [More...]
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2220-1                   security@debian.org
http://www.debian.org/security/                            Florian Weimer
April 19, 2011                         http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : request-tracker3.6, request-tracker3.8
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2011-1685 CVE-2011-1686 CVE-2011-1687 CVE-2011-1688 
                 CVE-2011-1689 CVE-2011-1690

Several vulnerabilities were in Request Tracker, an issue tracking
system.

CVE-2011-1685
    If the external custom field feature is enabled, Request Tracker
    allows authenticated users to execute arbitrary code with the
    permissions of the web server, possible triggered by a cross-site
    request forgery attack.  (External custom fields are disabled by
    default.)

CVE-2011-1686
    Multiple SQL injection attacks allow authenticated users to obtain
    data from the database in an unauthorized way.

CVE-2011-1687
    An information leak allows an authenticated privileged user to
    obtain sensitive information, such as encrypted passwords, via the
    search interface.

CVE-2011-1688
    When running under certain web servers (such as Lighttpd), Request
    Tracker is vulnerable to a directory traversal attack, allowing
    attackers to read any files accessible to the web server.  Request
    Tracker instances running under Apache or Nginx are not affected.

CVE-2011-1689
    Request Tracker contains multiple cross-site scripting
    vulnerabilities.

CVE-2011-1690
    Request Tracker enables attackers to redirect authentication
    credentials supplied by legitimate users to third-party servers.


For the oldstable distribution (lenny), these problems have been fixed
in version 3.6.7-5+lenny6 of the request-tracker3.6 package.

For the stable distribution (squeeze), these problems have been fixed
in version 3.8.8-7+squeeze1 of the request-tracker3.8 package.

For the testing distribution (wheezy) and the unstable distribution
(sid), these problems have been fixed in version 3.8.10-1 of the
request-tracker3.8 package.

We recommend that you upgrade your Request Tracker packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
 
< Prev   Next >
    
Partner

 

Latest Features
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Using the sec-wall Security Proxy
Yesterday's Edition
PNoy phone hacker denies vandalism
Prism doesn't have CIOs in a panic -- yet
7 essentials for defending against DDoS attacks
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2013 Guardian Digital, Inc. All rights reserved.