Your message dated Sat, 04 Nov 2023 12:47:13 +0000
with message-id <[email protected]>
and subject line Bug#1054516: fixed in request-tracker4 4.4.6+dfsg-1.1+deb12u1
has caused the Debian Bug report #1054516,
regarding request-tracker4: CVE-2023-41259 CVE-2023-41260
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1054516: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054516
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: request-tracker4
Version: 4.4.6+dfsg-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 4.4.6+dfsg-1.1
Control: found -1 4.4.4+dfsg-2+deb11u2
Control: found -1 4.4.4+dfsg-2
Control: found -1 4.4.3-2+deb10u2
Control: found -1 4.4.3-2

Hi Andrew, Dominic, Niko

The following vulnerabilities were published for request-tracker4.
Filling it in BTS for visiblity there, and for tracking status in the
various suites.

CVE-2023-41259[0]:
| RT is vulnerable to accepting unvalidated RT email headers in
| incoming email and the mail-gateway REST interface. This vulnerability
| is assigned CVE-2023-41259.

CVE-2023-41260[1]:
| RT is vulnerable to information leakage via response messages returned
| from requests sent via the mail-gateway REST interface. This vulnerability
| is assigned CVE-2023-41260.

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-41259
    https://www.cve.org/CVERecord?id=CVE-2023-41259
[1] https://security-tracker.debian.org/tracker/CVE-2023-41260
    https://www.cve.org/CVERecord?id=CVE-2023-41260
[2] https://github.com/bestpractical/rt/releases/tag/rt-4.4.7

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: request-tracker4
Source-Version: 4.4.6+dfsg-1.1+deb12u1
Done: Andrew Ruthven <[email protected]>

We believe that the bug you reported is fixed in the latest version of
request-tracker4, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andrew Ruthven <[email protected]> (supplier of updated request-tracker4 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 25 Oct 2023 22:32:15 +1300
Source: request-tracker4
Architecture: source
Version: 4.4.6+dfsg-1.1+deb12u1
Distribution: bookworm-security
Urgency: medium
Maintainer: Andrew Ruthven <[email protected]>
Changed-By: Andrew Ruthven <[email protected]>
Closes: 1054516
Changes:
 request-tracker4 (4.4.6+dfsg-1.1+deb12u1) bookworm-security; urgency=medium
 .
   * Apply upstream patch which fixes several security vulnerabilities
     (Closes: #1054516).
     - [CVE-2023-41259] Vulnerablility to unvalidated email headers in
       incoming email and the mail-gateway REST interface.
     - [CVE-2023-41260] Information leakage via response messages returned
       from requests sent via the mail-gateway REST interface.
   * Replace patches from 4.4.6+dfsg-1.1 with git-dpm managed patches:
     - Switch-to-Test-MockTime-HiRes-in-date-api-test.diff
     - Update-tests-for-EN-datetime-locale-change-to-space.diff
   * Add upstream fix to tests for FTBFS due to expired certs.
Checksums-Sha1:
 afe55f037df3622f6f6946852885a9d5eb13851c 5978 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.dsc
 a94cec5d6a6068fb07b8545343400a45b13214e6 3175260 
request-tracker4_4.4.6+dfsg.orig-third-party-source.tar.gz
 42047a4f7dc71c6fd51749c82aed3d6c3364f32a 10783318 
request-tracker4_4.4.6+dfsg.orig.tar.gz
 605eccf4536aa753c59e8daae593db36cb396050 455 
request-tracker4_4.4.6+dfsg.orig.tar.gz.asc
 ea61808acbfb7b74e28ad46220227254bf9c35a8 148136 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.debian.tar.xz
 5c67a48f2d3d548998f8fecd55b400096306c8b7 20758 
request-tracker4_4.4.6+dfsg-1.1+deb12u1_amd64.buildinfo
Checksums-Sha256:
 1a7e17f215a9ba9b4066c09b5b05c37dc33391d36a62cc3bcf7a42400ef59675 5978 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.dsc
 c60bce0df49c477ae50f61836dccdfd63a2bd6abb696e093688c15be7f0966a3 3175260 
request-tracker4_4.4.6+dfsg.orig-third-party-source.tar.gz
 1eff5bd9e556b5d6682ccd0e5b2f3dcc2c49a9ec4e215dadb90c4caf5e435e9e 10783318 
request-tracker4_4.4.6+dfsg.orig.tar.gz
 f93cefaa0c4d5047118168aa2212752fe4e5906d8696bcf8fc287a2345b53a71 455 
request-tracker4_4.4.6+dfsg.orig.tar.gz.asc
 f0dc53e9295e5133159fbc83e0a90944bb15d8827d5a38e52155d775388af4a6 148136 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.debian.tar.xz
 b3ecb084fb10c2fb1d5673f0c1b15f23c07b16a878086cef0e506dd263d4de16 20758 
request-tracker4_4.4.6+dfsg-1.1+deb12u1_amd64.buildinfo
Files:
 4fb5f923b7bc49c675568277301ebd9f 5978 misc optional 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.dsc
 1fe827bf2c3d69960d70627209c49b9d 3175260 misc optional 
request-tracker4_4.4.6+dfsg.orig-third-party-source.tar.gz
 a34cde135dd5407df89d4a7ac752252f 10783318 misc optional 
request-tracker4_4.4.6+dfsg.orig.tar.gz
 22d6678e6122cbdf290bbcc7d66ed6ca 455 misc optional 
request-tracker4_4.4.6+dfsg.orig.tar.gz.asc
 92ebc10c25310952bf2d1ac634a1d616 148136 misc optional 
request-tracker4_4.4.6+dfsg-1.1+deb12u1.debian.tar.xz
 83fae7898d7c56b0dd457362122e38c1 20758 misc optional 
request-tracker4_4.4.6+dfsg-1.1+deb12u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEExgP8TmAPHOzRyNl8S1PZMeTT6GMFAmU/djEACgkQS1PZMeTT
6GO5exAAnGLOpXKurMm22kd5T1jTqbENA35Rjt4UKJWFyqmV0FimNE1AQCsu18sy
Wf0eFYleiqriYq+xNlJvR4vcfeqj3wweKs2Vz6jwGsfFPPMY7w16OHUirms/C3cu
wRfsNgEYeBN/ymT6C01bzjz/PubeuELqEWzHSAeKl1uoYgY2U0Ir1EIhr4DM+tdh
nPQSo6diXPy578fkMg6MdTbJwujIIOkSAIRgPDKfGHUIeAZdU3hHwATTqjxtU1gD
xRjPnHtwfNlunvUe3q4qoDoDl0r167lqgoMsQZ47WrzyM+vgDuWrFWjLNbChd8R9
Rm5dDdT7zbKsNIjc7ha/OzLsISUSWbCeT0M0IiGDYiczEgpJC2z5FhqmUSquWbIw
/gE18ZvvqLcoZAUcPmNATBYaXK5APIHNGpnBHznf5Eg7Mk9Pp9votS85Ik8P1Jlv
0PbhD+YzoQDsl2c+K7dgpEqLuLh719ldr1V7M/hVco2Cjwl7pkomAfSqSBObgr2N
Kl693uhdfFWVFa8k+9okPnJX4IHu2QkmrtZH9XSIhOs78l2t5AEIaiExFE76UFbd
4YsDSEzckEXqR+u+Xk4j0hclDM/jaE1+XZ34+bwBw7mxxJzUJnkwmrKbIqsllp/i
OzRNR5U49MIBDgH6FfJR3k71EAEPRvYU+WObDiEp/edefzY7Sic=
=KBJo
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to