Your message dated Wed, 07 May 2025 12:20:13 +0000
with message-id <[email protected]>
and subject line Bug#1104739: fixed in znuny 6.5.15-2
has caused the Debian Bug report #1104739,
regarding znuny: CVE-2025-43926 CVE-2025-26847
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1104739: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1104739
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: znuny
Version: 6.5.14-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: fixed -1 6.5.15-1

Hi,

The following vulnerabilities were published for znuny and fixed
already in experimental, filling bugs to make it (potentially) on the
release team radar (if we want to make them to include in trixie).

CVE-2025-43926[0]:
| ZSA-2025-07: An agent with a valid session can elevate his permission
| via XSS by modifying his own preferences.


CVE-2025-26847[1]:
| ZSA-2025-06: Support bundles generated by the Support Data
| Collector may have unmasked password in the included system
| configuration export.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-43926
    https://www.cve.org/CVERecord?id=CVE-2025-43926
[1] https://security-tracker.debian.org/tracker/CVE-2025-26847
    https://www.cve.org/CVERecord?id=CVE-2025-26847

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: znuny
Source-Version: 6.5.15-2
Done: Patrick Matthäi <[email protected]>

We believe that the bug you reported is fixed in the latest version of
znuny, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <[email protected]> (supplier of updated znuny package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 07 May 2025 14:00:14 +0200
Source: znuny
Architecture: source
Version: 6.5.15-2
Distribution: unstable
Urgency: medium
Maintainer: Patrick Matthäi <[email protected]>
Changed-By: Patrick Matthäi <[email protected]>
Closes: 1104739
Changes:
 znuny (6.5.15-2) unstable; urgency=medium
 .
   * Uploading to unstable.
     Closes: #1104739
Checksums-Sha1:
 ec16b4069b0ce064441557840709b75954b8bd83 1826 znuny_6.5.15-2.dsc
 cb0ec2ed8f88e5b0c0acbc3599645763a07e7f0e 43737749 znuny_6.5.15.orig.tar.gz
 e0cae4876652906716a8d96e713b1883cbe58257 56512 znuny_6.5.15-2.debian.tar.xz
 5e71154917c46f4f6e85f2cb732c9c74d08bc89d 6357 znuny_6.5.15-2_source.buildinfo
Checksums-Sha256:
 ee8a54dc3a2dc40771d424ab2b0ff9885aa1949f9a548c347493080120d8f4e8 1826 
znuny_6.5.15-2.dsc
 d7edf8d45b50017ec1fe188631769622daebd7136850fcd71ecad9e6e4b19596 43737749 
znuny_6.5.15.orig.tar.gz
 581329082604ecf84c7d9ec6f8de67a9129cbd326f8505a12dc5d6aabcc6240e 56512 
znuny_6.5.15-2.debian.tar.xz
 74e9a52c983b5f021b749b1a90898a9b9444626b97f3c3fcc61ed10282d4820d 6357 
znuny_6.5.15-2_source.buildinfo
Files:
 26b089e1079482a4b2359a39ef56d175 1826 non-free/web optional znuny_6.5.15-2.dsc
 b3c4ba5947ac45538677e12a94a5a2ba 43737749 non-free/web optional 
znuny_6.5.15.orig.tar.gz
 355e48fffcec82f50fc9dd92fdc3107e 56512 non-free/web optional 
znuny_6.5.15-2.debian.tar.xz
 813b4f059cdcd9ad6a50ffa3f8fa59aa 6357 non-free/web optional 
znuny_6.5.15-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEWKA9xYJCWk3IuQ4TEtmwSpDL2OQFAmgbS3gACgkQEtmwSpDL
2ORaZw/9FJ96CeSleKkY83VepRVhg+ZV5xJS116Jfwi8KXHaprLOO7YqIMp9Jl+r
VSfLWNpmdFJmdjTpa2wHx68dd6Z++pbty7ybRp/wAtimuzUVNBlr/+Iu+2THlsJl
u+WNgBuHxwHoTiXwy8qcDw1ocNdsLliC+LqiPqeMlAydv9gPpS/B0uqfhIripyjl
zQ/v7P43OQ/QIE7Gfn5IMCToCXMf8BxhWiyc+QXQWLXfrlhwRQCEaH+Dgi94IjwV
/+kyArvLBOKfuf5ygFPqpngfPtv+NlnTnz0+wDJSi0R8euCGL1w/dQMbOnzfsFzz
CYjCbcwUmNG8RkWzO+nIgiybGfA7J1H1nqfLTX/wf3xlxCsocEAsS0WLWRtP8rSt
S2xU+n1VJTu6M/JFbtAS6xyCgK4ELjl6ckI2HYEAiFQUSrVIvtOFl0bXyj2mr0gQ
WwM/EuT7k60X3I10gwEmq4vxYVuNcEPL7x46Ip4vdLlGX9hD8J2Z+XvvaEVHNQ4N
pXxacoDiua56bnQSjeZoA/yyBTholCc/VixSPcPKidPGm5SVKvIJZOLr4H7SqdKP
JvGfj1x3KsYy1lMpBiOezQnIWJ3/iSSNSpcsH3KiqhzxUd+dzVYbvpmPvGmcMg5l
8DS40lmOUj85r1F4U6jbRLkxaHI6Dr3vxYHibVtzXIS3FDFmVBY=
=2xly
-----END PGP SIGNATURE-----

Attachment: pgp9fCH0hEPcr.pgp
Description: PGP signature


--- End Message ---

Reply via email to