CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:N/I:N/A:C
AI Score
Confidence
High
EPSS
Percentile
86.6%
Package : request-tracker3.8
Version : 3.8.8-7+squeeze8
CVE ID : CVE-2014-9472 CVE-2015-1165 CVE-2015-1464
Multiple vulnerabilities have been discovered in Request Tracker, an
extensible trouble-ticket tracking system. The Common Vulnerabilities
and Exposures project identifies the following problems:
CVE-2014-9472
Christian Loos discovered a remote denial of service vulnerability,
exploitable via the email gateway and affecting any installation
which accepts mail from untrusted sources. Depending on RT's
logging configuration, a remote attacker can take advantage of
this flaw to cause CPU and excessive disk usage.
CVE-2015-1165
Christian Loos discovered an information disclosure flaw which may
reveal RSS feeds URLs, and thus ticket data.
CVE-2015-1464
It was discovered that RSS feed URLs can be leveraged to perform
session hijacking, allowing a user with the URL to log in as the
user that created the feed.
For the oldstable distribution (squeeze), these problems have been fixed
in version 3.8.8-7+squeeze9.
We recommend that you upgrade your request-tracker3.8 packages.
Attachment:
signature.asc
Description: Digital signature
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | all | rt3.8-apache2 | < 3.8.8-7+squeeze8 | rt3.8-apache2_3.8.8-7+squeeze8_all.deb |
Debian | 7 | all | request-tracker4 | < 4.0.7-5+deb7u3 | request-tracker4_4.0.7-5+deb7u3_all.deb |
Debian | 6 | all | rt3.8-db-mysql | < 3.8.8-7+squeeze8 | rt3.8-db-mysql_3.8.8-7+squeeze8_all.deb |
Debian | 7 | all | rt4-db-postgresql | < 4.0.7-5+deb7u3 | rt4-db-postgresql_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-clients | < 4.0.7-5+deb7u3 | rt4-clients_4.0.7-5+deb7u3_all.deb |
Debian | 6 | all | rt3.8-db-sqlite | < 3.8.8-7+squeeze8 | rt3.8-db-sqlite_3.8.8-7+squeeze8_all.deb |
Debian | 6 | all | rt3.8-db-postgresql | < 3.8.8-7+squeeze8 | rt3.8-db-postgresql_3.8.8-7+squeeze8_all.deb |
Debian | 7 | all | rt4-db-sqlite | < 4.0.7-5+deb7u3 | rt4-db-sqlite_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-fcgi | < 4.0.7-5+deb7u3 | rt4-fcgi_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-apache2 | < 4.0.7-5+deb7u3 | rt4-apache2_4.0.7-5+deb7u3_all.deb |