-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 07 Jan 2015 10:11:37 +0100 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.1.7+dfsg1-8+deb7u5 Distribution: wheezy-security Urgency: high Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Patrick Matthäi <pmatthaei@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.1.7+dfsg1-8+deb7u5) wheezy-security; urgency=high . * Add patch 37-CVE-2014-9324 which fixes CVE-2014-9324, also known as OSA-2014-06: An attacker with valid OTRS credentials could access and manipulate ticket data of other users via the GenericInterface, if a ticket webservice is configured and not additionally secured. Checksums-Sha1: 42c4c978cb50686291279df5e60764d8eb52b6fc 1831 otrs2_3.1.7+dfsg1-8+deb7u5.dsc efc262b4ff605de1de6a741d133c3a661f07c96c 54502 otrs2_3.1.7+dfsg1-8+deb7u5.debian.tar.gz 30ed2e7e0ba9963eef2363c71be7d9d4a88c25f4 9763900 otrs2_3.1.7+dfsg1-8+deb7u5_all.deb e889ebc103a73f493fd7ae866121b50a49e3012b 137068 otrs_3.1.7+dfsg1-8+deb7u5_all.deb Checksums-Sha256: dd174e3b167944c219a07ff84e0b0066f1b8bf07f6d07e4d868c77c507a57b30 1831 otrs2_3.1.7+dfsg1-8+deb7u5.dsc 5f6f6efe8df5f20572e678b5ab9dc047bd3be9da422853f055a3aa4fb4e68190 54502 otrs2_3.1.7+dfsg1-8+deb7u5.debian.tar.gz f27113b4931a974ead8e500f47c909efb8a5771c601bc04c0d41ec51ea25b6a7 9763900 otrs2_3.1.7+dfsg1-8+deb7u5_all.deb 850c27be832b86bfa78811b55189e39efe2ffce83328417faae74ee804febb4c 137068 otrs_3.1.7+dfsg1-8+deb7u5_all.deb Files: 363d0f0c1b16f01d306d40cba8ae7d04 1831 web optional otrs2_3.1.7+dfsg1-8+deb7u5.dsc 230e7668d4048a31f82ee2181450c03c 54502 web optional otrs2_3.1.7+dfsg1-8+deb7u5.debian.tar.gz cc8cb60c8166c8d36276509154146df6 9763900 web optional otrs2_3.1.7+dfsg1-8+deb7u5_all.deb 9696103f53251a4244b7788bfdf34237 137068 web optional otrs_3.1.7+dfsg1-8+deb7u5_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJUro5fAAoJEBLZsEqQy9jk/AoQAIhwcz+n9IkYiUN5jOKRkT8O AQ6r3d4k6D5wPoOD0DQ7cp/coXS2v8f/4C5TtRZs7yn/bMB8Vk7jF0l12OfEaidH 3OrOjLuOEl/EPtvqcXBWV6JP1AHUKAGvT5Gp9A3NPyS4OKGx76h4RiOlOIIgIzFJ x1K7rm6qKN57wBSnX0aar7IhSFJPp96Wq+TA8uCCHMnehsM7I5ZynU22vE0o/DPr 5kY2p58lqahbBxkKI2pMOABi+Wx98a9iL5n7DQexPnwNWgQZCreCr1J8nsUrdH2G jYnnFsrNus3VeHlp8nVOSKQC3/DowoNg6ZASJyxuE0mS61rJB+RMxPGbyR7yKTGE sK3BgqkFbSCZxQkwCsMemQLcYR60DozobVelWgCpTjOg3bjYe3XUZhvPKJQgUtWf 659VFjAxvx90k4WkSVbO66OAGeQpLWLQS39vGBvVxMSlhKdZijwG3e9N4uARcXjg fVh5S2wbIfedAVdSpu39eWqZkPZic2HYZNJBTRWSn2H1r1EdhP+4ZnFyunIMLSLe CG//HIQtEqtabfEFAwDrxlfocyhycT2sPmvFKuidZ4e8YUKRXf417OeHMAsYNB8k YUbGrWUwylpupezMYrXlWvjMVId2Tfld8DKrbsryps1wgbNsD0y+17BUCwVLCl2d EmqwXHwDC7FUKqnPLDML =LoHP -----END PGP SIGNATURE-----