Linux Compatible

  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter

Advertisement


Latest News

[ Windows | Linux | Apple ]

· Linux Mint Debian Edition Released
· iPod Shuffle 4th Generation Teardown
· New version of Windows Storage Server due by the end of September
· Ubuntu 10.10 beta review
· Budget Sub-$150 Solid State Drive Round-up
· 7-Zip 9.16 Beta released
· CompatDB Updates 09/08/10
· Tech Report back-to-school 2010 system guide
· Firefox 4.0 Beta 5 released
· New typo3-src packages for Debian

Upcoming News

· Memonex Race R310 16GB Flash Drive Review @ OCC
· TRENDnet TEW-691GR 450Mbps WiFi-N Router @ Benchmark Reviews
· Cooler Master HAF 912 Review @ OCC
· Corsair H70 Self-Contained Liquid CPU Cooler @ Techgage.com
· Fedora Weekly News 242
· REVIEW: PNY GTX 460 XLR8 1GB @ PureOverclock
· Seagate FreeAgent Go 500Gb Portable Hard Drive @ TestFreaks
· ANNOUNCE: GENIUS 1.0.10 the "Back in Cali" release
· Meld 1.3.3 released
· DeepCool Gamer Storm Heatsink Review

Linux Compatibility

· Acer Aspire Timelinex 5820tg
· Notebook GX620
· IBM Thinkpad R50e
· BricsCAD for Linux
· Sil 3512 - Silicon Image Serial ATA (SATA) controller
· AverMedia AVerTV Volar Black HD (A850)
· SyncMaster B1930 monitor
· ATI Radeon 9600 Pro
· Compaq Presario CQ40
· Aspire 5741

New Forum Topics

· Ballistics..........
by: danleff
on: 2010-09-06 06:49
1 replies, 218 views

· Warhammer 40k Chaos Gate on XP - help?
by: Nateski
on: 2010-09-03 14:13
113 replies, 96482 views

· Need for Speed II: SE problem with Windows XP
by: nullphobiamaddy
on: 2010-08-31 18:46
5 replies, 20647 views

· mouse stops working once windows xp loads...help
by: cole1434
on: 2010-08-30 05:28
6 replies, 1302 views

· Dungeon Keeper 2 on vista
by: littlecengiz
on: 2010-08-26 08:47
1 replies, 1218 views

News Channels

· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS

What's New

Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2009 » DSA 1944-1: New request-tracker packages fix session hijack vulnerability

DSA 1944-1: New request-tracker packages fix session hijack vulnerability

Posted by: Bob on: 12/03/2009 01:10 PM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1944-1 security@debian.org
http://www.debian.org/security/ Steffen Joeris
December 03, 2009 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : request-tracker3.4/request-tracker3.6
Vulnerability : session hijack
Problem type : remote
Debian-specific: no
CVE Id : CVE-2009-3585


Mikal Gule discovered that request-tracker, an extensible trouble-ticket
tracking system, is prone to an attack, where an attacker with access
to the same domain can hijack a user's RT session.


For the stable distribution (lenny), this problem has been fixed in
version 3.6.7-5+lenny3.

For the oldstable distribution (etch), this problem has been fixed in
version 3.6.1-4+etch1 of request-tracker3.6 and version 3.4.5-2+etch1
of request-tracker3.4.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 3.6.9-2.

We recommend that you upgrade your request-tracker packages.


Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Debian (oldstable)
- ------------------

Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/r/request-tracker3.4/request-tracker3.4_3.4.5-2+etch1.diff.gz
Size/MD5 checksum: 24450 41891b8a012e671b706facdf4ece3402
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.1-4+etch1.diff.gz
Size/MD5 checksum: 23488 3c3914d16ad3e719cd502e2490561cc0
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.1-4+etch1.dsc
Size/MD5 checksum: 916 c03c1972b5ccab3574f9dfdd3fec0bee
http://security.debian.org/pool/updates/main/r/request-tracker3.4/request-tracker3.4_3.4.5-2+etch1.dsc
Size/MD5 checksum: 876 5a18cf29db217c6fd2265f6923a938cb
http://security.debian.org/pool/updates/main/r/request-tracker3.4/request-tracker3.4_3.4.5.orig.tar.gz
Size/MD5 checksum: 1410154 16c8007cba54669e6c9de95cfc680b2a
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.1.orig.tar.gz
Size/MD5 checksum: 1545708 40c5a828fadaeef9e150255a517d0b17

Architecture independent packages:

http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-apache2_3.6.1-4+etch1_all.deb
Size/MD5 checksum: 118264 318517b3d5539a84dee1639710048d92
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-apache_3.6.1-4+etch1_all.deb
Size/MD5 checksum: 117786 6f3da07edc9499cc282ceed8e71cf26d
http://security.debian.org/pool/updates/main/r/request-tracker3.4/rt3.4-clients_3.4.5-2+etch1_all.deb
Size/MD5 checksum: 120578 e404452bd2f9128255550644b26c72de
http://security.debian.org/pool/updates/main/r/request-tracker3.4/request-tracker3.4_3.4.5-2+etch1_all.deb
Size/MD5 checksum: 1198788 9af1648e53a722155dfd9acaaaf364cd
http://security.debian.org/pool/updates/main/r/request-tracker3.4/rt3.4-apache_3.4.5-2+etch1_all.deb
Size/MD5 checksum: 92002 009fe1090c6142409210f3304f63240d
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.1-4+etch1_all.deb
Size/MD5 checksum: 1315556 9a06544261bd4b7800ae89065d4f4317
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-clients_3.6.1-4+etch1_all.deb
Size/MD5 checksum: 146902 8c4a83429ef704025849373a24cf06d5
http://security.debian.org/pool/updates/main/r/request-tracker3.4/rt3.4-apache2_3.4.5-2+etch1_all.deb
Size/MD5 checksum: 92402 2737f376b27e6c3087dd355e5977edb5


Debian GNU/Linux 5.0 alias lenny
- --------------------------------

Debian (stable)
- ---------------

Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.7.orig.tar.gz
Size/MD5 checksum: 1764471 46c0b29cd14010ee6a3f181743aeb6ef
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.7-5+lenny3.dsc
Size/MD5 checksum: 1623 b8a904d8fa89cf4ea78fce2d95d95701
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.7-5+lenny3.diff.gz
Size/MD5 checksum: 51485 7b588a81fe9cbaa4bd9ac7d07b76d8f8

Architecture independent packages:

http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-db-mysql_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 185574 f71cdd55d18a69d908eea7f35434098c
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-db-sqlite_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 185676 82fe2682e028c113f469117937649636
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-apache2_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 187274 15328ffc1f76bd4e864c9c0faf4a4724
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-db-postgresql_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 185576 6c40b8a471370911da6e12cdc6b85727
http://security.debian.org/pool/updates/main/r/request-tracker3.6/request-tracker3.6_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 1540476 9d2cff7aca09a68a7b2707f91a6272ca
http://security.debian.org/pool/updates/main/r/request-tracker3.6/rt3.6-clients_3.6.7-5+lenny3_all.deb
Size/MD5 checksum: 215800 5052e370d018a81b9b786eb539b7cb05


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAksXmlIACgkQ62zWxYk/rQe7CwCffi6lD3X3MxWHeaRR4DcBZsnK
ApQAoILoVRZB9DlEMUGfVn8mQv803rrB
=Ywu+
-----END PGP SIGNATURE-----


Bookmark and Share

« DSA 1943-1: New openldap2.3/openldap packages fix SSL certificate verification weakness · RHSA-2009:1635-01 Important: kernel-rt security, bug fix, and enhancement update »

Linux Compatible » News » December 2009 » DSA 1944-1: New request-tracker packages fix session hijack vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2010 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition