CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:N/I:N/A:C
AI Score
Confidence
Low
EPSS
Percentile
86.6%
Debian Security Advisory DSA-3176-1 [email protected]
http://www.debian.org/security/ Salvatore Bonaccorso
February 26, 2015 http://www.debian.org/security/faq
Package : request-tracker4
CVE ID : CVE-2014-9472 CVE-2015-1165 CVE-2015-1464
Multiple vulnerabilities have been discovered in Request Tracker, an
extensible trouble-ticket tracking system. The Common Vulnerabilities
and Exposures project identifies the following problems:
CVE-2014-9472
Christian Loos discovered a remote denial of service vulnerability,
exploitable via the email gateway and affecting any installation
which accepts mail from untrusted sources. Depending on RT's
logging configuration, a remote attacker can take advantage of
this flaw to cause CPU and excessive disk usage.
CVE-2015-1165
Christian Loos discovered an information disclosure flaw which may
reveal RSS feeds URLs, and thus ticket data.
CVE-2015-1464
It was discovered that RSS feed URLs can be leveraged to perform
session hijacking, allowing a user with the URL to log in as the
user that created the feed.
For the stable distribution (wheezy), these problems have been fixed in
version 4.0.7-5+deb7u3.
For the unstable distribution (sid), these problems have been fixed in
version 4.2.8-3.
We recommend that you upgrade your request-tracker4 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | all | rt3.8-db-sqlite | < 3.8.8-7+squeeze8 | rt3.8-db-sqlite_3.8.8-7+squeeze8_all.deb |
Debian | 7 | all | rt4-apache2 | < 4.0.7-5+deb7u3 | rt4-apache2_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-db-postgresql | < 4.0.7-5+deb7u3 | rt4-db-postgresql_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-db-sqlite | < 4.0.7-5+deb7u3 | rt4-db-sqlite_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-fcgi | < 4.0.7-5+deb7u3 | rt4-fcgi_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | rt4-clients | < 4.0.7-5+deb7u3 | rt4-clients_4.0.7-5+deb7u3_all.deb |
Debian | 7 | all | request-tracker4 | < 4.0.7-5+deb7u3 | request-tracker4_4.0.7-5+deb7u3_all.deb |
Debian | 6 | all | rt3.8-clients | < 3.8.8-7+squeeze8 | rt3.8-clients_3.8.8-7+squeeze8_all.deb |
Debian | 6 | all | rt3.8-db-mysql | < 3.8.8-7+squeeze8 | rt3.8-db-mysql_3.8.8-7+squeeze8_all.deb |
Debian | 7 | all | rt4-db-mysql | < 4.0.7-5+deb7u3 | rt4-db-mysql_4.0.7-5+deb7u3_all.deb |