-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 27 May 2013 09:07:43 +0200 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.2.7-1 Distribution: unstable Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.2.7-1) unstable; urgency=high . * New upstream release. - Security fix for CVE-2013-3551, also known as OSA-2013-03: An attacker with a valid agent login could manipulate URLs in the ticket split mechanism to see contents of tickets and they are not permitted to see. - Refresh hunky patch 07-dont-chown-links. - Refresh hunky patch 10-nice-packagemanager-permissions-message. - Rewrite patch 11-fix-SetPermissions-to-include-some-more-dirs. * Merge 3.1.7+dfsg1-8+deb7u1 changelog. * Permission fixes from debian/rules removed, again. * Install new upstream changelog CHANGES.md. Checksums-Sha1: 4269384b838b813a8a996d27e7879ac864cd51ff 1755 otrs2_3.2.7-1.dsc 7138f03384741066e70594e3e4a80841fd0d68dd 21572249 otrs2_3.2.7.orig.tar.gz 70082aab7488bbc44c212f19a7a6ac9c5e3f54a2 37916 otrs2_3.2.7-1.debian.tar.gz 0ed37f961466bdf677ed5535838531f204f79351 4417036 otrs2_3.2.7-1_all.deb bbbf0b40b71dcc35d27ba000dd21c8954bebd539 159352 otrs_3.2.7-1_all.deb Checksums-Sha256: d2690a31d6e3aea2eb06df1837181f713934b7fa19bb1c694a4a729b632d904c 1755 otrs2_3.2.7-1.dsc f6f5440a48e76ccd404b78997779248909c22f1e07affb4ab408917dd1a817d5 21572249 otrs2_3.2.7.orig.tar.gz de9a21a640a3b01d39fb769cbaa9f4d5f6033d2f32a7fde4db6bd7e8b30d7cd7 37916 otrs2_3.2.7-1.debian.tar.gz d30acfb143a6f0fa0033e6ee4eecd67828e16d5c86c05067f74f3477783e3dd1 4417036 otrs2_3.2.7-1_all.deb 90f7cd3ae5af14924b1a0e48b905394036dd5d9653cc13eb98121049cfd25384 159352 otrs_3.2.7-1_all.deb Files: 4d07d697f8ccb83aa3b09fc5d271dce0 1755 web optional otrs2_3.2.7-1.dsc 15df4495b3d3b84cf1f07ee6475bfdc6 21572249 web optional otrs2_3.2.7.orig.tar.gz 92bc4211389631a0cfcd5ae5621c03ec 37916 web optional otrs2_3.2.7-1.debian.tar.gz 1dcfbf6a9f0fca10d351c9599c239c50 4417036 web optional otrs2_3.2.7-1_all.deb 3e70f7db409034a5f54f27872fcff483 159352 web optional otrs_3.2.7-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJRowo9AAoJEBLZsEqQy9jkuBEQAJWvGpY4ZgN4FJQv09PNrNYF Dk0LlMck2mMp/FsVkXUphObtjUzTSanDYzh41RLgMFifTAThALeyPxNNQOBfZy59 s9OiGy6VDptK4oNJmaKnZEOCUvYSkoJL1RwBNWEvobsXrQr0zKsmjx6EIFGqzlcr ZQBCzMv24I0ogifM0ndMl3wRshSA1XD8xz7rx8+YOFWcmaQcJNW+phyJAN+EwrsP XAZkPOgjeKFQLfdEixwHAUoItqX9bxOPGiJ+qO7QtQit3PxRggFs6DIA9imN7Ro4 l/GGcGntPiZpFv6SFjz2/EbmDPDt1n4SXB82leGeY6fHlmkAoqpC8V7VBROKDvkp kauMlRwSkX4ZgltXbHm67C+oL/2imliFExyw0AudDhse208dWJfNoE5I68UTlSTF qyZTvEuqmWiJH8TGI/p0ENKV5IBv8O6UAonCD8pmP1rkFBp9F+lWuMVYOFbqMvWx chrR/DHA5kActv2zmsvVtpvB+vAvYet5nT7sf7YCq0+LpG5h4vTObHfVYcXuv8oi diSMjDeBl182Vh8o6mu/nc9PlI9HeZUJAESQIqiFdPJUUhdHboiGRmeXVxyo3e8T M6NSH4FEkco4Uu3w9HMOpIxWtLe22ykhFUQRP8rBmZ+uN2nBLGYQj+HvVIzsTK+n 88NJZlwqvE981n05163F =+tWf -----END PGP SIGNATURE-----