-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 23 Aug 2012 19:16:08 +0200 Source: otrs2 Binary: otrs2 Architecture: source all Version: 2.4.9+dfsg1-3+squeeze3 Distribution: stable-security Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs2 - Open Ticket Request System Changes: otrs2 (2.4.9+dfsg1-3+squeeze3) stable-security; urgency=high . * Add upstream patch 17-security-osa-2012-01 from OSA-2012-01, which fixes a XSS vulnerability described in CVE-2012-2582 when using the Internet Explorer on viewing e-mails. * Add upstream patch 18-security-tag-nesting to improve HTML security to detect tag nasting. Checksums-Sha1: 158702149ba2e09db1fefe43eeaaa13eb76591f3 1789 otrs2_2.4.9+dfsg1-3+squeeze3.dsc a1318d798b03eaf933f1802f89d7193fc9cf4363 33170 otrs2_2.4.9+dfsg1-3+squeeze3.debian.tar.gz 369f70ef5b9a470f992cff70c0585f1d73c94db2 4092882 otrs2_2.4.9+dfsg1-3+squeeze3_all.deb Checksums-Sha256: f1dda0d6f06517391350afc1e79972f821bff35b083e5c19a1c31d672d19bf77 1789 otrs2_2.4.9+dfsg1-3+squeeze3.dsc 963f1d8f31ee6e5d7be414e31d74dde97f39a2600afefdb0545da3f8801ebafa 33170 otrs2_2.4.9+dfsg1-3+squeeze3.debian.tar.gz cd904d0b3b3350df44831c7d7842354677aa6450cf32a30db9ddb92878d99db6 4092882 otrs2_2.4.9+dfsg1-3+squeeze3_all.deb Files: 34ea08fb281ed9caf5d814bfa27e9a76 1789 web optional otrs2_2.4.9+dfsg1-3+squeeze3.dsc 6272de6f9023fd06c5355a90e514c3cd 33170 web optional otrs2_2.4.9+dfsg1-3+squeeze3.debian.tar.gz 0990ae4de6bdf719939d585b2006afba 4092882 web optional otrs2_2.4.9+dfsg1-3+squeeze3_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJQPSbKAAoJEBLZsEqQy9jkyyYP/226TvKl20+2OsZvwg/YUGtL zTx1bc+dhz4xbEXExdVvQBgyJCcTrv2P006ycSb5XMSJi6c54LYjlIYHARf6O+R/ 7v9o0B62n00vJP8+lAt3PhTiA29Txsc1RKwRRJU+nw+xg6mmoqRQ+5pR2l6yTaAw 5gNhnXUHBCB6wK8jsUvGEGQ+k/6AJjhJwuUr//c9EWbTLP+AE/Z02eh19nY7NvoZ +RjOgqf2DutQCHEEycwRvRw9cmZNMMRbgZ4yb1rsHYOmwvW7MytJHYKEHTOQmep8 oMR8k0T4zRG3LTJMblDsra1SLeeIr6ij8FuUtJFMvVCIQGAxti2k7vAQmAKJviDO VB10tRCMF5uF2FadngFTPCxj/SA+x1dZ1GERQJqqG4AgEmgphz1pGD8kOoTYYlaT kLg8cUkowOx0TE3PB1VeA3rm4MvD/tbf6qCVY33pglQFfwriWnlA1rNGtshodq0H oGkpvTsoBYfnX7PkZL1smyZv0v9XWGvN25lDNoTWk0kjW7hno9K2hVP7h0HMu0dy 5UJqCqsz9IDQPFOPZTSNLvbQRwHf47GpW/uUXLBHSHZHauZggxWytkQ/der5XXR0 aekq+fKEjpQZOpHwhQRhZzrS0hNU0mG7tcCPAIxUpgUEidSMt2kwCA+z5CnGg/5Q yD9++ACjyQQE9l84z29/ =IQOZ -----END PGP SIGNATURE-----