-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Feb 2019 19:03:02 +0100 Source: collabtive Binary: collabtive Architecture: source all Version: 2.0+dfsg-5+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Gunnar Wolf <gwolf@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: collabtive - Web-based project management software Changes: collabtive (2.0+dfsg-5+deb8u1) debian-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2015-0258 Due to missing checks an attacker could upload scripts, which would execute code on the server by accessing for example avatar images. Checksums-Sha1: 0bcfcc788ad4589a87ad67d37816b550de4a1f06 1979 collabtive_2.0+dfsg-5+deb8u1.dsc 7b583dac92bdddaf4f0195ca661bb295abe4a905 4513618 collabtive_2.0+dfsg.orig.tar.gz 8c736c5646c22718b1fdbd1b1c13dbf363d90d2a 45604 collabtive_2.0+dfsg-5+deb8u1.debian.tar.xz 7a7244e699781a9da2ac61afcec977aa3dc577c9 2852262 collabtive_2.0+dfsg-5+deb8u1_all.deb Checksums-Sha256: 51f39ef69d5a9c1870d1ab963722a09537031acc9baaf6aaa209d88c7ffdaa36 1979 collabtive_2.0+dfsg-5+deb8u1.dsc 42139b644dbc02cbe584389d79bc3b990f135a7012351ab51d0cff02fb508554 4513618 collabtive_2.0+dfsg.orig.tar.gz 540bbcf2237283ab767b84de0c82c0df3b969e294dbe7dc2fad450a2a5d21273 45604 collabtive_2.0+dfsg-5+deb8u1.debian.tar.xz 3c940db52ca5735a26c1830a9a778c929e556f817c3e5c181611c55de15a9fbb 2852262 collabtive_2.0+dfsg-5+deb8u1_all.deb Files: 1d9cecb2160d58ea5725608b348c1118 1979 web optional collabtive_2.0+dfsg-5+deb8u1.dsc a6785a2d3f182ec83d7bd69f402a7125 4513618 web optional collabtive_2.0+dfsg.orig.tar.gz 152cd3b772fd1c0c44e28f37a10b4bba 45604 web optional collabtive_2.0+dfsg-5+deb8u1.debian.tar.xz b34112d9a7a01d201196f7ca17ca5660 2852262 web optional collabtive_2.0+dfsg-5+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl5ZXu5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRxUeEAC8OJZVYer3cm6o7EQwJV1DvoWDfN24 7nNcyZuRSSlNqWSlK6aMcrLh1tmsEdGxmXXBk1Y1THMMmJ7oy2A77edNdw3p8QJK 30zUyVcymwiZYy1GLRz7m8AUSqGUGcO/svNTP1JdQXnHfOOKpMhvG2wT/c4wAEgG bn0dMA4nQu/klNgDz6W/24PmQ5gkjK+FR/iTJ1/l4678CA3sxxIipE31O04Vw3rY vrzyrDoBO03ZRRcpzLLatKOdhVBuUf6zIaLcF2B/IZOINab1rzpt6wLERiHOlNs+ Lz5x3tZXHYFFo6A5nIuU5IW+WG1OJUwp448HWEBJDvmzFWDV8QX2MTKMGKJdWsr8 3XRIjRPt4xBjZFzg6yNwBOTHfpwC1nGddfx6k2yiw9zWFyKCxgD+mXP5rkrT799K ySRFxNFDUNPSJoOVr0yLV7Qpow/9bHRBgd/QvJ5PITdabJsHi4IpgOp1+cUZVJ7A lqRbj1w61ljDbPPE43605G2ZZifzk3LZQT4U0A+bcnTHiolx7Ned1U14szg6vv6g 2p25I+pQCSIKuRzl5teKnMa9AxB8qxgAAA6yo2RrzDXxwSE8qyo/lcxwqHWEmgvh LtVSr+3uammznvs3Dy5XTGO9nkFSMlGdk8XKmkfUUucETsegSgU2CuCF5IxzgL7P ENRg9u4FvOefsA== =pTpN -----END PGP SIGNATURE-----