Debian Package Tracker
Register | Log in
Subscribe

request-tracker4

Choose email to subscribe with

general
  • source: request-tracker4 (main)
  • version: 4.4.6+dfsg-1.1+deb12u3
  • maintainer: Debian Request Tracker Group (archive) (DMD)
  • uploaders: Andrew Ruthven [DMD] – Niko Tyni [DMD] – Dominic Hargreaves [DMD]
  • arch: all
  • std-ver: 4.1.5
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.4.4+dfsg-2+deb11u3
  • o-o-sec: 4.4.4+dfsg-2+deb11u5
  • oldstable: 4.4.6+dfsg-1.1+deb12u3
  • old-sec: 4.4.6+dfsg-1.1+deb12u3
versioned links
  • 4.4.4+dfsg-2+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.4.4+dfsg-2+deb11u5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.4.6+dfsg-1.1+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • request-tracker4
  • rt4-apache2
  • rt4-clients
  • rt4-db-mysql
  • rt4-db-postgresql
  • rt4-db-sqlite
  • rt4-doc-html
  • rt4-fcgi
  • rt4-standalone
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:00:26
    Last run: 2026-05-26T17:48:26.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:02:54
    Last run: 2025-04-06T06:53:23.000Z
    Previous status: unknown

Created: 2026-05-26 Last update: 2026-05-29 15:48
7 security issues in bullseye high

There are 7 open security issues in bullseye.

7 important issues:
  • CVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
  • CVE-2026-41073: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by avoiding opening exported RT spreadsheet files directly in spreadsheet applications when the data may contain untrusted user input.
  • CVE-2026-41075: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restricting RT account access to trusted users.
  • CVE-2026-41076: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by reviewing their LDAP server's authentication policy to ensure it rejects unauthenticated bind attempts. Upgrading RT remains the recommended fix.
  • CVE-2026-44227:
  • CVE-2026-44229:
  • CVE-2026-44231:
Created: 2026-05-20 Last update: 2026-05-26 19:00
7 security issues in bookworm high

There are 7 open security issues in bookworm.

7 important issues:
  • CVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
  • CVE-2026-41073: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by avoiding opening exported RT spreadsheet files directly in spreadsheet applications when the data may contain untrusted user input.
  • CVE-2026-41075: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restricting RT account access to trusted users.
  • CVE-2026-41076: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by reviewing their LDAP server's authentication policy to ensure it rejects unauthenticated bind attempts. Upgrading RT remains the recommended fix.
  • CVE-2026-44227:
  • CVE-2026-44229:
  • CVE-2026-44231:
Created: 2026-05-20 Last update: 2026-05-26 19:00
10 security issues in sid high

There are 10 open security issues in sid.

10 important issues:
  • CVE-2025-2545: Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
  • CVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser. This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
  • CVE-2025-30087: Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
  • CVE-2025-61873: Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
  • CVE-2026-41073: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by avoiding opening exported RT spreadsheet files directly in spreadsheet applications when the data may contain untrusted user input.
  • CVE-2026-41075: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restricting RT account access to trusted users.
  • CVE-2026-41076: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by reviewing their LDAP server's authentication policy to ensure it rejects unauthenticated bind attempts. Upgrading RT remains the recommended fix.
  • CVE-2026-44227:
  • CVE-2026-44229:
  • CVE-2026-44231:
Created: 2025-04-29 Last update: 2026-05-23 12:00
news
[rss feed]
  • [2026-05-26] Removed 4.4.7+dfsg-4 from unstable (Debian FTP Masters)
  • [2025-11-01] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u3 (source all) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2025-10-26] Accepted request-tracker4 4.4.4+dfsg-2+deb11u5 (source) into oldoldstable-security (Andrew Ruthven) (signed by: Thorsten Alteholz)
  • [2025-10-22] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u3 (source all) into oldstable-security (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2025-05-07] Accepted request-tracker4 4.4.4+dfsg-2+deb11u4 (source) into oldstable-security (Andrew Ruthven)
  • [2025-05-03] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2025-04-30] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u2 (source) into stable-security (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2025-04-11] request-tracker4 REMOVED from testing (Debian testing watch)
  • [2024-12-26] request-tracker4 4.4.7+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2024-12-21] Accepted request-tracker4 4.4.7+dfsg-4 (source) into unstable (Andrew Ruthven)
  • [2024-10-03] request-tracker4 4.4.7+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2024-09-27] Accepted request-tracker4 4.4.7+dfsg-3 (source) into unstable (Andrew Ruthven)
  • [2024-08-18] request-tracker4 4.4.7+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-13] Accepted request-tracker4 4.4.7+dfsg-2 (source) into unstable (Andrew Ruthven)
  • [2024-06-06] request-tracker4 4.4.7+dfsg-1.1 MIGRATED to testing (Debian testing watch)
  • [2024-05-31] Accepted request-tracker4 4.4.7+dfsg-1.1 (source) into unstable (Chris Hofstaedtler) (signed by: Christian Hofstaedtler)
  • [2023-11-07] Accepted request-tracker4 4.4.4+dfsg-2+deb11u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2023-11-04] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2023-10-31] request-tracker4 4.4.7+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-30] Accepted request-tracker4 4.4.3-2+deb10u3 (source) into oldoldstable (Andrew Ruthven)
  • [2023-10-30] Accepted request-tracker4 4.4.6+dfsg-1.1+deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2023-10-30] Accepted request-tracker4 4.4.4+dfsg-2+deb11u3 (source) into oldstable-security (Debian FTP Masters) (signed by: Andrew Ruthven)
  • [2023-10-29] Accepted request-tracker4 4.4.7+dfsg-1 (source) into unstable (Andrew Ruthven)
  • [2023-10-10] request-tracker4 4.4.6+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-10-10] request-tracker4 4.4.6+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-10-05] Accepted request-tracker4 4.4.6+dfsg-2 (source) into unstable (Andrew Ruthven)
  • [2023-03-08] request-tracker4 4.4.6+dfsg-1.1 MIGRATED to testing (Debian testing watch)
  • [2023-02-25] Accepted request-tracker4 4.4.6+dfsg-1.1 (source) into unstable (Adrian Bunk)
  • [2022-07-22] request-tracker4 4.4.6+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-19] Accepted request-tracker4 4.4.6+dfsg-1 (source) into unstable (Andrew Ruthven)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.4.7+dfsg-4syncable1
  • 13 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing