-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 27 Jan 2020 10:06:22 +0530 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.3.18-1+deb8u13 Distribution: jessie-security Urgency: medium Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Abhijith PA <abhijith@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.3.18-1+deb8u13) jessie-security; urgency=medium . * Non-maintainer upload by the Debian LTS Team. * Fix CVE-2020-1766: improper handling of uploaded images * Fix CVE-2020-1765: improper control of parameters allows spoofing * Fix CVE-2020-1767: unauthorized view of drafts Checksums-Sha1: 0d6fdc7541a8bb10ddff897f0b2b2b7805f901a3 1853 otrs2_3.3.18-1+deb8u13.dsc 7f45cf5336e9ce5d507a935241f042bdfdf85845 21067692 otrs2_3.3.18.orig.tar.bz2 cf9d99ec59a98950d2a685bca7dc329ec400f215 56696 otrs2_3.3.18-1+deb8u13.debian.tar.xz 77735a0ddc2e39aaabba46937234e719ee601815 5480796 otrs2_3.3.18-1+deb8u13_all.deb 329926be5fe62c3de67c1a6ce535d032f37598b3 189598 otrs_3.3.18-1+deb8u13_all.deb Checksums-Sha256: e0a88b171ed07792fe40b68172a76c9671c48a60df766a335e14d1c9d5133c90 1853 otrs2_3.3.18-1+deb8u13.dsc 9d6e4e44316c6812f35618be50d8951a0c2e0d917752610fada936c466bea453 21067692 otrs2_3.3.18.orig.tar.bz2 47510fec288b0d33d4be18a71cd41db643327aede9228280f96178598b91720a 56696 otrs2_3.3.18-1+deb8u13.debian.tar.xz b179ace7a159987519a01f751372cd0109337eebd48587313700341b080cfa27 5480796 otrs2_3.3.18-1+deb8u13_all.deb 37529e6bdb25a6c1e3757349ce26ebf7e3da945ef700ca4fec14fc56319a68f7 189598 otrs_3.3.18-1+deb8u13_all.deb Files: 9038be206066cb5819f5a600ee3bdfc4 1853 web optional otrs2_3.3.18-1+deb8u13.dsc b3375dfa09a2ec3c4cebc7ad74d55e0b 21067692 web optional otrs2_3.3.18.orig.tar.bz2 14a6ca3846053c755fcbc3dd7f1676bc 56696 web optional otrs2_3.3.18-1+deb8u13.debian.tar.xz 3568940bd57ea0ede6656c4b8c80faf3 5480796 web optional otrs2_3.3.18-1+deb8u13_all.deb 0d9ef8f3d98647ef5dff3c804648d5e2 189598 web optional otrs_3.3.18-1+deb8u13_all.deb -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAl4v0vYUHGFiaGlqaXRo QGRlYmlhbi5vcmcACgkQhj1N8u2cKO+mYBAAgawrTk16QzG0GCNswlqlT7vO80Z3 f0+LlSwGHDNQib7Kriua/2goCqSxQgGr7pQiQdQE0zroP2NolNwaPe/jseKmpydR Ji/8AiUwHKxu3RhLoDeptVkd5AOsn1Y6SWeTqENa5h/clf7wQE2tVAkwGhrnVVFX WxuTNAXq8nTaeskmF2b6QiDV5hHsgJuUrK0IU+mB/7DJFI20LiRh7LAwb7DlDJGM C+QaIMM7KVrvRTtxvXaMlfSGPrJE5h1IaTApcD5XaZrcI4siVNswQHsTv3VW/TqC /WHj8vTh3N9bdJ3oTlC3w72o64Y5fGIX7PtFApU3iZqN3BaM1cecv0fGmymbGtw+ tkyeMars3qkGpYJPmdbnrJm7EWM8Vsd9rzXnnkGHVgAlLiI8ddAvSkdCHxVb6jJP UEiF2/4XoSxYo0NNqKEftk0s2ENEveDbPMzcLqpftDiQqppkttmVjb/iIfJ0AvyQ dfCYdiHjNO8RhGvri5+ooVdnj14JErJ1ffF9VAl8U2nHYF/OJWBQjSqAk6nSOj2W LwDjpzMX+RDTHP3GPmoAkW/o8mKD25O1866gZyqMz9dE/tp/KXeAoHoORi2+QF6H 9uvjfX7K4ZLBdSKD6ILff5gNrY4W4mdS4PHS35A9WyhJmNo87mhh3kYmyHgYj9nB jfFFml9qisNTBNs= =/khA -----END PGP SIGNATURE-----