-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 08 Oct 2025 20:40:55 +1300 Source: request-tracker5 Binary: request-tracker5 rt5-apache2 rt5-clients rt5-db-mysql rt5-db-postgresql rt5-db-sqlite rt5-doc-html rt5-fcgi rt5-standalone Architecture: source all Version: 5.0.3+dfsg-3~deb12u4 Distribution: bookworm-security Urgency: medium Maintainer: Andrew Ruthven <andrew@etc.gen.nz> Changed-By: Andrew Ruthven <andrew@etc.gen.nz> Description: request-tracker5 - extensible trouble-ticket tracking system rt5-apache2 - Apache 2 specific files for request-tracker5 rt5-clients - mail gateway and command-line interface to request-tracker5 rt5-db-mysql - MySQL database backend for request-tracker5 rt5-db-postgresql - PostgreSQL database backend for request-tracker5 rt5-db-sqlite - SQLite database backend for request-tracker5 rt5-doc-html - HTML documentation for request-tracker5 rt5-fcgi - External FastCGI support for request-tracker5 rt5-standalone - Standalone web server support for request-tracker5 Changes: request-tracker5 (5.0.3+dfsg-3~deb12u4) bookworm-security; urgency=medium . * Apply upstream patch which fixes a security vulnerability. - [CVE-2025-61873] Fix CSV injection via ticket values with special characters that are exported to a TSV from search results. Checksums-Sha1: aba95fd2489cf1d99d9b5d3b33b62d2edeed9e35 6209 request-tracker5_5.0.3+dfsg-3~deb12u4.dsc ef0b663b6363cabf3845f7f6bd5b508d66b0929e 3217706 request-tracker5_5.0.3+dfsg.orig-third-party-source.tar.gz 4f043bd95000923aa8189403b73f52b720c534de 18601901 request-tracker5_5.0.3+dfsg.orig.tar.gz 307b425a830f9ff3df679e2d365a02a8c566bdcb 455 request-tracker5_5.0.3+dfsg.orig.tar.gz.asc 69494fb153d7097522554f6fc056220090b1a28c 169400 request-tracker5_5.0.3+dfsg-3~deb12u4.debian.tar.xz af8986f81c164ec2e8c59d352b51b9dd5199b775 12053744 request-tracker5_5.0.3+dfsg-3~deb12u4_all.deb 78dcbcdd164045378a195f7346be4497c1a61c4f 24705 request-tracker5_5.0.3+dfsg-3~deb12u4_amd64.buildinfo e76b2acf7d0f71bccadfe07f7119a09e36e3756e 21048 rt5-apache2_5.0.3+dfsg-3~deb12u4_all.deb b88a61b35f777e85032b8e9d1a46fcb18a146ddb 53380 rt5-clients_5.0.3+dfsg-3~deb12u4_all.deb 9f7e463df01204e540a268847c47fbc5579889de 20360 rt5-db-mysql_5.0.3+dfsg-3~deb12u4_all.deb 99258be3abbfc4f3c850a800d5874bd73476416b 20348 rt5-db-postgresql_5.0.3+dfsg-3~deb12u4_all.deb 7ec5ec8b2a3acc44acba3261d259ce1aabffa076 20452 rt5-db-sqlite_5.0.3+dfsg-3~deb12u4_all.deb 6d4549babf2fc2c262690f6fa605b2e81a983df1 4438580 rt5-doc-html_5.0.3+dfsg-3~deb12u4_all.deb 293da7bfcb417892f10625da4b01241a44ac3b65 23108 rt5-fcgi_5.0.3+dfsg-3~deb12u4_all.deb b43d156bc5d557d3eb6c4373cb4fb886e811f0d8 19820 rt5-standalone_5.0.3+dfsg-3~deb12u4_all.deb Checksums-Sha256: 6555d863d663813eeb36b38999ea0e3fd6f503a4060a316afcfe6a10157912fa 6209 request-tracker5_5.0.3+dfsg-3~deb12u4.dsc 49b856ff23be2f5265c7b3460ac3d49ef24e4462b8165d39fbb12b7776d0e66a 3217706 request-tracker5_5.0.3+dfsg.orig-third-party-source.tar.gz e23aee3cb291ccad5e521aeabe0fcd2f076bcfa8b7f801af498a7505e53d8441 18601901 request-tracker5_5.0.3+dfsg.orig.tar.gz 6cfc32a9bf2d09768a5ac2b103f21d6675dfc3490c06190562296e5b2082ccce 455 request-tracker5_5.0.3+dfsg.orig.tar.gz.asc 5f973f84b924f666471dd87b1e3385e7e3e041ffdc3c4abaf4dce9e1599fc200 169400 request-tracker5_5.0.3+dfsg-3~deb12u4.debian.tar.xz c90001928292f8539f038067511513bd1a33038aa03c7b1c23009d22c3eaff2b 12053744 request-tracker5_5.0.3+dfsg-3~deb12u4_all.deb 6a3542cf67abf5d95a8ec8ea35b9a8776ba4be08c3ae9df48f91c5ae7f7178f0 24705 request-tracker5_5.0.3+dfsg-3~deb12u4_amd64.buildinfo 744e20f692d09967318461694b34996fcbca1ee1e71003aad9c5cfb19ae71319 21048 rt5-apache2_5.0.3+dfsg-3~deb12u4_all.deb 049e5fd2dd2905d8b7d5e478769423d9d894baaeb1118494906b481d4d0b38b2 53380 rt5-clients_5.0.3+dfsg-3~deb12u4_all.deb 1cdc33a65e267588b031a188dd7f4bca57d8396b8ba4f3bb89926be5dda51ce2 20360 rt5-db-mysql_5.0.3+dfsg-3~deb12u4_all.deb 618e816f54e9816423999c75517307065fc279ab77efc4a071a3e056722acd51 20348 rt5-db-postgresql_5.0.3+dfsg-3~deb12u4_all.deb 7e692fd6047062ca6e13303b3ed41e55709035f71aaa92aacd7ba433f51bad8c 20452 rt5-db-sqlite_5.0.3+dfsg-3~deb12u4_all.deb b9f33405fc310738917c7fff6734a2b5fa864612558d2a581e796e40fdde0183 4438580 rt5-doc-html_5.0.3+dfsg-3~deb12u4_all.deb 159c4a36c1fbcd533e6874e1fe6993d4e77bc638eb0a43a0bca45ca994e54ca9 23108 rt5-fcgi_5.0.3+dfsg-3~deb12u4_all.deb 11a30095c5ef7e5ace163084304ce790b2f0a55a865f16c837fdd8ed8d17fbe1 19820 rt5-standalone_5.0.3+dfsg-3~deb12u4_all.deb Files: 921813fb24912ca3a4e1700a2a5a076c 6209 misc optional request-tracker5_5.0.3+dfsg-3~deb12u4.dsc 7e052f0715b42102e6387f6e398a6e87 3217706 misc optional request-tracker5_5.0.3+dfsg.orig-third-party-source.tar.gz ec8a8fc2fbbf1ccebb4825ca0e2aeac5 18601901 misc optional request-tracker5_5.0.3+dfsg.orig.tar.gz f52489a073fb418b7bc68a6bb672299e 455 misc optional request-tracker5_5.0.3+dfsg.orig.tar.gz.asc 2c797c2cf1ea38557f16ab3ba343fb7b 169400 misc optional request-tracker5_5.0.3+dfsg-3~deb12u4.debian.tar.xz 7e80f0c7d6aae24b4f405cb6afa6bec2 12053744 misc optional request-tracker5_5.0.3+dfsg-3~deb12u4_all.deb 078f1423a2f7714a2347d97f4d0aafea 24705 misc optional request-tracker5_5.0.3+dfsg-3~deb12u4_amd64.buildinfo 2f7b3496408dd5722cb8fa992124b489 21048 misc optional rt5-apache2_5.0.3+dfsg-3~deb12u4_all.deb 951f298d72a0711c0c4508b39fc48a37 53380 misc optional rt5-clients_5.0.3+dfsg-3~deb12u4_all.deb 1a3e1ac7e411ef541c0a34773056b645 20360 misc optional rt5-db-mysql_5.0.3+dfsg-3~deb12u4_all.deb 7ce2d19d9c254befce021c16c3ca11dd 20348 misc optional rt5-db-postgresql_5.0.3+dfsg-3~deb12u4_all.deb 1e8502dfe0bcd6c3dbe7eff6e3b25426 20452 misc optional rt5-db-sqlite_5.0.3+dfsg-3~deb12u4_all.deb f7cf6f7e531da398e437710479b37ba7 4438580 doc optional rt5-doc-html_5.0.3+dfsg-3~deb12u4_all.deb 46d4c3a770eee8a579a14a9cb65c26b4 23108 misc optional rt5-fcgi_5.0.3+dfsg-3~deb12u4_all.deb d9a6a7f00babf53729dc4d5d78a6e67a 19820 misc optional rt5-standalone_5.0.3+dfsg-3~deb12u4_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEExgP8TmAPHOzRyNl8S1PZMeTT6GMFAmj0OxAACgkQS1PZMeTT 6GMbOA/+NoNrlCTHr4cGJjyUmQ6/GwUhq5BLlFiijyqdhzahNZpbu72RQt0WfqZ7 ESXHGvj7ywI3eUimBY3EGdpXMF9vrs4CHKyv5uJFCO06ek7ugGZzV6Zpdy4gjOO+ Qd99Lvj+7lEDY64vOiqC78YgTws+4PodWzOYL24cvpeCrFk5h4Hl+gwnaoh64B+d VE6lFXLN6Ip956WwOhlcsHBzhvr+3fZNZyHYxX7mWhfMvqkYXyQ6vSYR3ufjHBxy RV4CeoC4I8/ZHo519eScTzgkx6bj5fuYZrnNMbBHZaGR5P11SnedKPpqKhKGqJrF sXxt78VxJbON+/yBJT/ncPQygeGME4F39chPBgNTGMTP6w4LBF52D7aQzlFd9Vwj yEI15IxZW/0XgmdMWibGXU7qM0A7Rh/WdkdKzWIjA/C67Pw0cjzzihLlhCcR8wbP nkXoLDjTbNZoHOEvjb88piL+Ca4Zm3bu68YvyJ8XKDZdfaJOIbeHXdqmoOnxY6Qc el5kED9n+4mBOhkyNJYhz4y/UTiNGDnJgW0rtQbcbbF9YM3FVU8L6+kcEm8jmIFr w4jgfxCAoAc/XeKxjeTGSPgNGr7FuqZ0/+tK14AMd30Cd+V8sJm4kWQxn4n38qBS d9pEAiGdocYcKeLp8t/vymYQGg9CGlLyjGYDOMsxhP+pArdM07E= =Dy83 -----END PGP SIGNATURE-----