Bugs fixes in "rt3.8-apache2"
Origin | Bug number | Title | Date fixed |
---|---|---|---|
CVE | CVE-2012-4884 | Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files | 2012-11-28 |
CVE | CVE-2012-4734 | Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn | 2012-11-28 |
CVE | CVE-2012-4732 | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before | 2012-11-28 |
CVE | CVE-2012-4730 | Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject a | 2012-11-28 |
CVE | CVE-2011-2082 | The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for | 2012-11-28 |
CVE | CVE-2011-4458 | Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows | 2012-11-28 |
CVE | CVE-2011-2085 | Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to | 2012-11-28 |
CVE | CVE-2011-2084 | Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ti | 2012-11-28 |
CVE | CVE-2011-2083 | Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote attackers to in | 2012-11-28 |
Launchpad | 1004834 | Multiple security vulnerabilities in request-tracker3.8 | 2012-11-28 |
About
-
Send Feedback to @ubuntu_updates