-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 20 Dec 2017 18:05:13 +0100 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.3.18-1~deb7u3 Distribution: wheezy-security Urgency: medium Maintainer: Patrick Matthäi <pmatthaei@debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Description: otrs - Open Ticket Request System (OTRS 3) otrs2 - Open Ticket Request System Changes: otrs2 (3.3.18-1~deb7u3) wheezy-security; urgency=medium . * 20-OSA-2017-10.diff: Fix for OSA-2017-10 aka CVE-2017-17476: Fix a session hijacking vulnerability on deployments with cookie support disabled by tricking a logged in agent to click on crafted links. Checksums-Sha1: e357b8f5a72a5abb3de9852fe08b27cbe29139e1 1806 otrs2_3.3.18-1~deb7u3.dsc 7f45cf5336e9ce5d507a935241f042bdfdf85845 21067692 otrs2_3.3.18.orig.tar.bz2 e2f865893e47fa111c9f65141e1fb5bba76d6429 49578 otrs2_3.3.18-1~deb7u3.debian.tar.gz 2ed58a6f5fbf2908ffb465ff12aebda568576ff2 10660600 otrs2_3.3.18-1~deb7u3_all.deb 1a483e2ca67d8849517430da9a6608577ec4cd54 189846 otrs_3.3.18-1~deb7u3_all.deb Checksums-Sha256: 58a6c622e14051fa1eb2fc4838b163648d7ec50bd778b6a16f8c7ae3446dc952 1806 otrs2_3.3.18-1~deb7u3.dsc 9d6e4e44316c6812f35618be50d8951a0c2e0d917752610fada936c466bea453 21067692 otrs2_3.3.18.orig.tar.bz2 3f79a7955169fd6a3989f6b7e727ed4d25c517d3c72122a45fb6f921988ebc06 49578 otrs2_3.3.18-1~deb7u3.debian.tar.gz 2126229bd08e6ec12055f94d5618cb575f1121c2a0f00f889cb01dceab20161e 10660600 otrs2_3.3.18-1~deb7u3_all.deb 0d9228a86f72a0b695f647263c6886035d513f450b5402bfdbfa3dd2e18b590c 189846 otrs_3.3.18-1~deb7u3_all.deb Files: 6e99abfa6c5dcbaf68a5229afd54e682 1806 web optional otrs2_3.3.18-1~deb7u3.dsc b3375dfa09a2ec3c4cebc7ad74d55e0b 21067692 web optional otrs2_3.3.18.orig.tar.bz2 de3b00ce49264d218093246b3320266c 49578 web optional otrs2_3.3.18-1~deb7u3.debian.tar.gz d2c354e553ea2e9452b9b8e64b90de2a 10660600 web optional otrs2_3.3.18-1~deb7u3_all.deb bce979b5bcccdead6e151404c9578197 189846 web optional otrs_3.3.18-1~deb7u3_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlo65v8ACgkQnUbEiOQ2 gwJpLRAAsCw7e/LDAgEmYu6mJE59CCL0y3zzJmiYziBlHyU2ma/YQsz2Ev6AcRYB sUwpyLz9BFWDRYGT1zPk671FuEL5tYom/hFaFa6XkLcnlPQCjKle6Ohu/RA6aRLB +/ayz5Ix+rV0eRu2vNRZ0sSeVjs8ZAY4ml0LWRM6Ieu51vFe52apNU8e5GA5YS7l jIpkMJmSK8DMMkXIVnPw4a/7XsDjrWTk18FLQlCbLKcIs6GlhoRXQsrShGOEJY88 QJW9dgsAK+lkL97U2UId016djkWVSBQ5wGqoT/0g2WWrXDln5TKPbkH8JDkLPTPV knCj1xsNdNQgD1ejWfdHiowkZUK/62ABQY4iGust0Ys+TOLP78ZHlUrWhe0ouK7q mopZQGo4f9TA8lv7q07hG/E+17Wk7A6MPivOYanESpbLUVwB+Be8zoxVCJygeE5o xOdm++DlmU80z+TKC+Mzr39jDa6L5hhn1k0zaFvXCf7HQnf89mQz38J9Dm9aVLgo kq8CmZKIpozLF1vzCNg9gX2kKGspJclbcq7exvGx0shUp9R870Arv1CLIoLr0co6 By9lo5h4Q31v9N5TfSlvG2Ed4TMeZtIq5CgOOO4T0KbZ3tT3DgKULouJb3I7Zem2 nawMTlmKRT0enE3jK+aRWnQ6eKHLvH072xiuA6zXXS5EHPGoMuo= =CnAt -----END PGP SIGNATURE-----