-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 24 May 2013 14:53:53 +0200 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.1.7+dfsg1-8+deb7u1 Distribution: stable-security Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.1.7+dfsg1-8+deb7u1) stable-security; urgency=high . * Add patch 32-CVE-2013-3551 which fixes CVE-2013-3551, also known as OSA-2013-03: An attacker with a valid agent login could manipulate URLs in the ticket split mechanism to see contents of tickets and they are not permitted to see. Checksums-Sha1: f329d74de5b49115ed1dd43688e3564c7e9decea 1831 otrs2_3.1.7+dfsg1-8+deb7u1.dsc e17abdc2dcdb401288864f53dc0f2ac5b15e8ac8 14045767 otrs2_3.1.7+dfsg1.orig.tar.gz 04631bdef4df52aeed6d0eccac6257bc94e2e246 50660 otrs2_3.1.7+dfsg1-8+deb7u1.debian.tar.gz dcefdb0b053083d5b8b724d33b754fdc15b8f10b 9762590 otrs2_3.1.7+dfsg1-8+deb7u1_all.deb 127569deb99cbc8f6ce1f5b65a83efd9cf936462 136766 otrs_3.1.7+dfsg1-8+deb7u1_all.deb Checksums-Sha256: 24ea6c6da6f7297389472dc35ce5ddb1293b68c0487691729c5f9dfd13c60f02 1831 otrs2_3.1.7+dfsg1-8+deb7u1.dsc 9ec218f996dd57893462a746ad7afd95ae390631c7bf608ac22c73bdfef4b583 14045767 otrs2_3.1.7+dfsg1.orig.tar.gz 97cf702938ae98fd85de49f854062a566d75c8286b67409f894006409e8284fd 50660 otrs2_3.1.7+dfsg1-8+deb7u1.debian.tar.gz 1dbd00948473aba3462fe3a80526bd9095598bfc82355fdfd9ec6b47bbb5d4ac 9762590 otrs2_3.1.7+dfsg1-8+deb7u1_all.deb 5606b6f859d3c89cafe4901017ba24ce60df5e772d5429d75681678b385d3021 136766 otrs_3.1.7+dfsg1-8+deb7u1_all.deb Files: 5a5ed34b0b40f84c4c13979e5fc2987c 1831 web optional otrs2_3.1.7+dfsg1-8+deb7u1.dsc 412f79688819836f6203b076e8aa588e 14045767 web optional otrs2_3.1.7+dfsg1.orig.tar.gz cb9421582bacba59a167d8eb54bb707a 50660 web optional otrs2_3.1.7+dfsg1-8+deb7u1.debian.tar.gz 05b99a9825626a984041e750b6577007 9762590 web optional otrs2_3.1.7+dfsg1-8+deb7u1_all.deb 567cce52de2a3758e6f7847b4a1adf59 136766 web optional otrs_3.1.7+dfsg1-8+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJRoiD7AAoJEBLZsEqQy9jkHXEP/1rSQO9wPS1tqvq24sSRdtTr mJ8dfLCpK8oTcFX3Gy/O6dtiq5IMi9sUBQz2GSqV2QUjrEYhMWmAFbj/wdeCRn3B Z7ATgd4cxQC1Hl9xJYR4OM226Wqt03qr28aZCzYIdOgJQzGRlOHdd3dSqE6X1o+m LLSGRaynktBUy3N/mwRXPXtSc82VioDEKiLZ042ITs6U3HGPFa9tBVYXSqVULtYV 44OpNnAGZg9h13cX8/mRYb6kNjHUPn2fCPal9rs80G98bq9fTm3v8HNogWW4oF/R F1KZ7qr1PkuGJIoXLIVKdMdZJLLVKDVBUHXwHDFcOeBVuxOGEWEpHxAlM3ChI9Cj fZIDaTP0KMTYLbbaRnDfcMBYxOcaU7+RwV8Z9rbjtphybx5IAgVYIEC2scldp1Kx p8kv1TlxfoQLB7XVq0Rs4QuHl/oyKUx40Ir7uTdmsc9+F4FV1Uu9us9oUVl/9TK3 K1pkmDYRW527Rs9XRgCVNk2U9/Z+XFuHHYGvgGEJ6x3ygtdDF23oU2r/M2SoAEUo L2FgQZkDJYlVvanqkDWMDGqp1aV3nxIaeSCn0//5+aLUnucMIQC4f0ATDTtRNj4Q n3xQ3UHQTGUD9E21GSMBsgSirMEFGoCBEhhf1Zr6JQlfULTJhC85xqGzJzi+bmIq DmWTw5pOYuhJVto7aySf =CRFy -----END PGP SIGNATURE-----