-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 16 Oct 2021 19:07:35 +0200 Source: redmine Binary: redmine redmine-mysql redmine-pgsql redmine-sqlite Architecture: source Version: 3.3.1-4+deb9u5 Distribution: stretch-security Urgency: high Maintainer: Antonio Terceiro <terceiro@debian.org> Changed-By: Sylvain Beucler <beuc@debian.org> Description: redmine - flexible project management web application redmine-mysql - metapackage providing MySQL dependencies for Redmine redmine-pgsql - metapackage providing PostgreSQL dependencies for Redmine redmine-sqlite - metapackage providing sqlite dependencies for Redmine Changes: redmine (3.3.1-4+deb9u5) stretch-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2021-42326: Redmine may disclose the names of users on activity views due to an insufficient access filter. Checksums-Sha1: 085294551f8c50c473832b00ded38bf71666758d 2823 redmine_3.3.1-4+deb9u5.dsc 36ad761a02fcd3881838b1ac2d248c175583ce0c 256008 redmine_3.3.1-4+deb9u5.debian.tar.xz bf85724999d40d12c17b7e4a2ebfd9e5c71862a2 10025 redmine_3.3.1-4+deb9u5_all.buildinfo Checksums-Sha256: a5fb17e342b0277d8c8b248f1481881abaf8b6add29aee47e14285942cd2deb1 2823 redmine_3.3.1-4+deb9u5.dsc b888605ff226af16184220c8b070c63a4ae6bced52f2cf756e9ab8499b507b7c 256008 redmine_3.3.1-4+deb9u5.debian.tar.xz 69e410b0bfcb77294dd360e948fced02652d5d9db44db8af7c1530ac380872fc 10025 redmine_3.3.1-4+deb9u5_all.buildinfo Files: d5990779cfb0d6335b797c5a9f09b37d 2823 web extra redmine_3.3.1-4+deb9u5.dsc d8a94a1558512fb1358e5b1cf4b61d44 256008 web extra redmine_3.3.1-4+deb9u5.debian.tar.xz 2b66af0afd05a4f81ab4f24fa8ee40b1 10025 web extra redmine_3.3.1-4+deb9u5_all.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmFtkX0ACgkQDTl9HeUl XjAPPRAAucl1qbR+lCjg/BuoY5cyZtBiH95PVilmiYLqlYcYGXiKbuqkCGbTHK5Z 99YkeNPyx24BbICJQVVNTYtKRhqrwZf39BPGX/pTgw+GfJ58HMeLn6NAgQczAzAF aTjn5RxWw6DMF6weWNq4C5O4IWR4RPp9bJnDU+ZrVeCgYQT8ZQPcVIemtSZ+22i7 WN2GqWjeP2eXd890S8+iD1kEVVKA91dSJXst5mRV5dTJzqOTh9b7uU0eMA3qHrQz cICDRvHdF+v/D07CMjmbWsKgUGlL6VssYO6KoB21IfAS9VXI/1y4ypJ+IEyp06sI MRwoqLRgaKQC0pAApCpcj5vh/I1lSD9tK/Y+I+HuALQDhMTyZ1xN4nq+sqULUOrL qF5V5ib615AmT8cn757TkmOGjrlDKEZJkM5q/9EwxOzgqpALGuH3u3SR1yTPonc/ lFEMZc1Qvc1Ce0auawTxNlvbUPMJzWkpso78cEYp4J5w0zqszdc3iv0yvo5DapxC co7zExAwZQo1EaRrPlqx9/WjELzhJaxCFaNKGzi+flsh3B5nMoEYKnQmWzM13LMD ezezUpm/GGPInWxuel043chFp1guHNlpgzCC/8Ed39oWYfxIcsAktOKZo32Flxui oVEnJlN1TJcJo+bfdRSPc02OkDloLSEZ0YyOHgK69mzMvdAgGt0= =F2Sr -----END PGP SIGNATURE-----