Re: jquery / CVE-2019-11358

2019-05-03 Thread Brian May
Brian May writes: > $ /usr/bin/uglifyjs --unsafe ./dist/jquery.js -v Looks like that command reads from STDIN, not the specified file. Now changed the Makefile to use: $ /usr/bin/uglifyjs --unsafe < ./dist/jquery.js which appears to work. Updated patch attached. -- Brian May diff -Nru

Accepted otrs2 3.3.18-1+deb8u9 (source all) into oldstable

2019-05-03 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 03 May 2019 10:37:13 +0200 Source: otrs2 Binary: otrs2 otrs Architecture: source all Version: 3.3.18-1+deb8u9 Distribution: jessie-security Urgency: high Maintainer: Patrick Matthäi Changed-By: Markus Koschany Description:

[SECURITY] [DLA 1774-1] otrs2 security update

2019-05-03 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: otrs2 Version: 3.3.18-1+deb8u9 CVE ID : CVE-2019-9892 A flaw was discovered in OTRS, the Open Ticket Request System. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to