-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 18 Jun 2013 13:56:46 +0200 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.1.7+dfsg1-8+deb7u2 Distribution: stable-security Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.1.7+dfsg1-8+deb7u2) stable-security; urgency=high . * Add patch 33-CVE-2013-4088 which fixes CVE-2013-4088, also known as OSA-2013-04: An attacker with a valid agent login could manipulate URLs in the ticket watch mechanism to see contents of tickets they are not permitted to see. Checksums-Sha1: f70b31188ad90a440b6678bd9f491fd1c8b28de6 1831 otrs2_3.1.7+dfsg1-8+deb7u2.dsc 9637f193fa1fec67cb96e653d59088a7e4d2a8f9 50844 otrs2_3.1.7+dfsg1-8+deb7u2.debian.tar.gz 5f737e9c7c2b1460a55323e45f5745691b069f9c 9762788 otrs2_3.1.7+dfsg1-8+deb7u2_all.deb 05c835cba5aad693959ef5ad718328d9a11924ab 136800 otrs_3.1.7+dfsg1-8+deb7u2_all.deb Checksums-Sha256: 8021bc21a6d661cc4db0da45b808cf558b5347f4b6bf95db7774b91825bdd12e 1831 otrs2_3.1.7+dfsg1-8+deb7u2.dsc 530af11ceb5d50d5e5834fec488d83f00ddb11d7790f1f94e4b6ce2e70a96dbd 50844 otrs2_3.1.7+dfsg1-8+deb7u2.debian.tar.gz 33eed55bbc1d1c9b041fb7a779c3425aa2162ca259fe37a64ee9b81e61e035ab 9762788 otrs2_3.1.7+dfsg1-8+deb7u2_all.deb ff2fa4048becaf6a8a3525cde1ff631288da00153715269e7a9e26e742e22c85 136800 otrs_3.1.7+dfsg1-8+deb7u2_all.deb Files: ca521a1c71e4816ee68a31585fd8eadc 1831 web optional otrs2_3.1.7+dfsg1-8+deb7u2.dsc e90642c8da65a11592fe10f9fc239b70 50844 web optional otrs2_3.1.7+dfsg1-8+deb7u2.debian.tar.gz be8b8171c2f27ac14e8d1bca7b7e7a62 9762788 web optional otrs2_3.1.7+dfsg1-8+deb7u2_all.deb 9c7cc9588d1662a8c727ff039b0d0500 136800 web optional otrs_3.1.7+dfsg1-8+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJRwbvrAAoJEBLZsEqQy9jkOzkP/RyLLYouPXnZjki8VX4thBNB PLtKAU1Jlz0MNiI5sSlg5sE4Z8nMvIt1x2ZSCRJIqi8+Z92AMgv/v34trQcLM8uM pSx9R7DhfnGspkTsrTtymlcnBiArP5mzfVlIPJcYye1IeO8f11tf+iX80HcbnitM gNmlbokPFjbi9eLTdy6Ac3bOeJ9vXoEmJdewpq6lycN9v0lU+B+DD3+wirHaQpAF xZ1q7TvSV0O2iGW4a0a628lSWLSb2JitvPhs/FneT3Ym2TIDcbIfjmVOsZo/Iug7 b2ijnpKsQ2LnClS9YIOdeeqTkI9fFbnIX1Qqvtxh9SSS3L6plO+WLvtAwYwVml9G FmPYV/YTeNpnDOSgswjHb4isF7ljR3EpoCn25HXyMo+LRERxBOQfXnNQ/BVH2dYV pNlGAkMK6ji/nAy2yjdmUj8bjIyIw14gYEGbDTL+85bqhaBSoF6lk0DCmXVslJnq Br4bkEFBcEdMMWL4gtSe0SCrRcpUFHmBQV0uPaYMyW8fDsxliJxQ1cZc4EV/fE3P kMAH9xaEV2xJuTPZLOnE+PT1U3q66uWHW5yIPRVzpprtbdQb9LREiJbUa+8+uhTy Jlu1tUmI22DFItizJsz+TcpcpirQenQiPl0dr6nSRFzGv+4yR4xeztWjyB5OvFnQ G49S+mANBR4nuWlNohCF =618S -----END PGP SIGNATURE-----