Bug#683288: rt-authen-externalauth: privilege escalation

2012-08-10 Thread Tom Jampen
tag 683288 pending thanks On 30.07.2012 16:55, Yves-Alexis Perez wrote: For Wheezy, please fix this with an isolated fix instead of updating to a new upstream release (since the freeze is in effect) Fixed in git. Tom -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with

Bug#683288: rt-authen-externalauth: privilege escalation

2012-07-30 Thread Yves-Alexis Perez
Package: rt-authen-externalauth Severity: grave Tags: security Justification: user security hole Hi, a security issue has been found in rt-authen-externalauth package. From http://blog.bestpractical.com/2012/07/security-vulnerabilities-in-three-commonly-deployed-rt-extensions.html: