Multiple vulnerabilities have been discovered in Request Tracker, an
extensible trouble-ticket tracking system. The Common Vulnerabilities
and Exposures project identifies the following problems:
- CVE-2014-9472
Christian Loos discovered a remote denial of service vulnerability,
exploitable via the email gateway and affecting any installation
which accepts mail from untrusted sources. Depending on RT’s
logging configuration, a remote attacker can take advantage of
this flaw to cause CPU and excessive disk usage.
- CVE-2015-1165
Christian Loos discovered an information disclosure flaw which may
reveal RSS feeds URLs, and thus ticket data.
- CVE-2015-1464
It was discovered that RSS feed URLs can be leveraged to perform
session hijacking, allowing a user with the URL to log in as the
user that created the feed.
For the stable distribution (wheezy), these problems have been fixed in
version 4.0.7-5+deb7u3.
For the unstable distribution (sid), these problems have been fixed in
version 4.2.8-3.
We recommend that you upgrade your request-tracker4 packages.