request-tracker3.8 3.8.10-1ubuntu0.1 source package in Ubuntu

Changelog

request-tracker3.8 (3.8.10-1ubuntu0.1) oneiric-security; urgency=low

  * SECURITY UPDATE: Multiple security fixes (LP: #1004834):
    - Email header injection attack (CVE-2012-4730)
    - CSRF protection allows attack on bookmarks (CVE-2012-4732)
    - Confused deputy attack for non-logged-in users (CVE-2012-4734)
    - Multiple message signing/encryption attacks related to GnuPG
      (CVE-2012-4735)
    - Arbitrary command-line argument injection to GnuPG (CVE-2012-4884)
    - XSS vulnerabilities (CVE-2011-2083)
    - information disclosure vulnerabilities including password hash
      exposure and correspondence disclosure to privileged users
      (CVE-2011-2084)
    - CSRF vulnerabilities allowing information disclosure,
      privilege escalation, and arbitrary code execution. Original
      behaviour may be restored by setting $RestrictReferrer to 0 for
      installations which rely on it (CVE-2011-2085)
    - remote code execution vulnerabilities including in VERP
      functionality (CVE-2011-4458)
  * Fix the vulnerable-passwords script to also upgrade password hashes
    for disabled users, and rerun the script in postinst (CVE-2011-2082)
  * Include clean-user-txns script to accompany the above fixes, and
    run in postinst
  * Provide specific instructions for restarting a mod_perl based
    Apache server
  * debian/patches/60_misc_sec_regressions.dpatch: fix regression in
    rt-email-dashboards, and whitelist search results and calendar helper
    from CSRF protection
 -- Marc Deslauriers <email address hidden>   Fri, 09 Nov 2012 15:08:36 -0500

Upload details

Uploaded by:
Marc Deslauriers on 2012-11-09
Uploaded to:
Oneiric
Original maintainer:
Ubuntu Developers
Component:
main
Architectures:
all
Section:
misc
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Oneiric updates on 2012-11-27 universe misc
Oneiric security on 2012-11-27 universe misc

Builds

Oneiric: [FULLYBUILT] i386

Downloads

File Size MD5 Checksum
request-tracker3.8_3.8.10.orig.tar.gz 5.4 MiB 00c147d71476d032d33dbad76bdc06ff
request-tracker3.8_3.8.10-1ubuntu0.1.diff.gz 114.7 KiB 116010e00be653283f2f8695f3afd3ea
request-tracker3.8_3.8.10-1ubuntu0.1.dsc 2.3 KiB 86f80592f4a84638b6cb0daf680ff8d8

View changes file

Binary packages built by this source

request-tracker3.8: extensible trouble-ticket tracking system

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the core of RT.
 .
 This package supports three database types out of the box: MySQL,
 PostgreSQL and SQLite. In order to support a zero-configuration install,
 SQLite will be used by default, but is not recommended for production
 use. Please see /usr/share/doc/request-tracker3.8/NOTES.Debian for more
 details and consider installing rt3.8-db-postgresql or rt3.8-db-mysql at
 the same time as this package.

rt3.8-apache2: Apache 2 specific files for request-tracker3.8

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides various configuration files and manages the
 necessary dependencies for running request tracker (RT) version 3.8
 on the Apache 2 web server.

rt3.8-clients: mail gateway and command-line interface to request-tracker3.8

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides support for injecting tickets into Request Tracker
 from a mail server via rt-mailgate. It may be installed onto any
 machine where you want to use the "rt" command-line interface.

rt3.8-db-mysql: MySQL database backend for request-tracker3.8

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides dependencies and dbconfig-common support for
 using Request Tracker version 3.8 with a MySQL database.

rt3.8-db-postgresql: PostgreSQL database backend for request-tracker3.8

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides dependencies and dbconfig-common support for
 using Request Tracker version 3.8 with a PostgreSQL database.

rt3.8-db-sqlite: SQLite database backend for request-tracker3.8

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt3.8-clients).
 .
 This package provides the 3.8 series of RT. It can be installed alongside
 the 3.6 series without any problems.
 .
 RT is a high-level, portable, platform independent system that eases
 collaboration within organizations and makes it easy for them to take care
 of their customers.
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides dependencies and dbconfig-common support for
 using Request Tracker version 3.8 with a local SQLite (version 3) database.
 .
 This package will be pulled in by default by request-tracker3.8, but SQLite
 is not recommended for production use. Please see
 /usr/share/doc/request-tracker3.8/NOTES.Debian for more details and
 consider installing rt3.8-db-postgresql or rt3.8-db-mysql instead of this
 package.