-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 31 Mar 2020 10:46:34 +0200 Source: otrs2 Binary: otrs otrs2 Architecture: source all Version: 6.0.27-1 Distribution: unstable Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs - Open Ticket Request System (OTRS 6) otrs2 - Open Ticket Request System Changes: otrs2 (6.0.27-1) unstable; urgency=high . * New upstream release. - Fixes CVE-2020-1773, also known as OSA-2020-10: It is possible that an authenticated user guess other session IDs based on its own. Also it is possible to guess a password reset token or an automated password generated. Checksums-Sha1: 7466a05bad69f27f6de0a9efe8bd1bbc8c5fef1b 1817 otrs2_6.0.27-1.dsc 64c915947e2cc53b76eb0fa19afc0a65b52dc64e 25824690 otrs2_6.0.27.orig.tar.bz2 bb408eea17be41bbe9501a79b23d9d3dfcb65a3f 30692 otrs2_6.0.27-1.debian.tar.xz 2a0702c348039e6bf51b6c49a714f150720515a8 9830248 otrs2_6.0.27-1_all.deb 7fac2f15c6f48726e604f7f2d2945c7acf4110ec 6553 otrs2_6.0.27-1_amd64.buildinfo 1495866baa040479f448bd2afe39a8190e6591e5 258388 otrs_6.0.27-1_all.deb Checksums-Sha256: 477407143c93001e68ac1238cd1663331aa576b26d705f3d81d4a8b4c182575c 1817 otrs2_6.0.27-1.dsc 3e3be27c2b6a5a0a61736a7744e3eee426f1aee295e9fd768adf0b76c72ec0d7 25824690 otrs2_6.0.27.orig.tar.bz2 7b12bce1fa286e05bb24a4ff16c566e9d0a0ef591436ebe509c054db6bee8e08 30692 otrs2_6.0.27-1.debian.tar.xz c110ec6d5973634cf132b6ce4b6b885b5562e268224fc59b30517f0556233e13 9830248 otrs2_6.0.27-1_all.deb aa082ec6f8a859a37c617939bfd9e4602da479b6df9b2f62531fac70126f232a 6553 otrs2_6.0.27-1_amd64.buildinfo 4b1158812a385d761a58e30b43404c82e78ae755a2eae1c67503af4207a6fd7b 258388 otrs_6.0.27-1_all.deb Files: 02495bb5a55e05aa225af45f4e843fe6 1817 non-free/web optional otrs2_6.0.27-1.dsc 46096a8f5bf74527bdcc438942b52796 25824690 non-free/web optional otrs2_6.0.27.orig.tar.bz2 3cda9313bbc4134d5ede30bb31025360 30692 non-free/web optional otrs2_6.0.27-1.debian.tar.xz a71113940c0b58cd2933ae0787f0ae50 9830248 non-free/web optional otrs2_6.0.27-1_all.deb 565eab4b0fd2caef08e4eee100a1f279 6553 non-free/web optional otrs2_6.0.27-1_amd64.buildinfo b4c357a7d9066ad56aed5ab8502f94b8 258388 non-free/web optional otrs_6.0.27-1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEWKA9xYJCWk3IuQ4TEtmwSpDL2OQFAl6DDdcACgkQEtmwSpDL 2OSfpw//ex6glGRQ/0ondoUwUAesgydKsSLuQYL98vU5yaM0iPjdms+c1lSDs9g4 UYbDD1izOi+UrWYdl2xK4Lzw8wSHLOO6LOcNlDLHAOElU3y6Qw+thYkSIUz4ob/C mkEE0I8mi1qTvuWAabfJx9POEr9148ubW9SDZ4zMW7mqZlU7MfQDuHGDORzQLWop FFvN0bRGUZb6u72myyiTOyw1EmiSa3fE25oiXsjv72HTDdwzg0WnwVIp5sqRgQKs wzx5ndjui6hOrDtrB4P5Ex+BAH0JSR/sHdClFxdikjjHlc3xy8aqIFvom3ssA3Xg 054DVlYKoPTnWa7i2FFXLwMqBG2J6s4YbbJ8l2ImWPeOJw28ajl344yw6GFnOJN9 LRPqspHcV6VjHidDIZr1z1WEHE1tvdXmjH7X6o9et3XeptvQd47wrDa8YWnF0mCf BJGhqmabOena4c+aoAEvigBmGlM9oBs1ey3018iZUXp2jXXiz1CNpJC/8+XMe52Y 1c0aYa51T4Z3hrB1WauabWh2gJZMukqI+Zn4OXJSkUTGSOgjleJu6NAW8B2dui4u ML7IPUA0IApYX0cNEkCsNTfThy9cIsnAxGgeEZHYSVbN/PkKufvBZWHVoB+a7Qoe 9dptFccSu5ZwWs5sysO6Ge0lC1nC8DV1S3I9YZWN+MStm00/KGI= =enBk -----END PGP SIGNATURE-----