lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <874nqnymrw.fsf@mid.deneb.enyo.de>
Date: Thu, 07 Jun 2012 20:55:47 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: debian-security-announce@...ts.debian.org
Subject: [SECURITY] [DSA 2480-3] request-tracker3.8
	regression update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2480-3                   security@...ian.org
http://www.debian.org/security/                            Florian Weimer
June 07, 2012                          http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : request-tracker3.8
Vulnerability  : regression
Debian Bug     : 674924 675369

The recent security updates for request-tracker3.8, DSA-2480-1 and
DSA-2480-2, contained another regression when running under mod_perl.

Please note that if you run request-tracker3.8 under the Apache web
server, you must stop and start Apache manually.  The "restart"
mechanism is not recommended, especially when using mod_perl.

For the stable distribution (squeeze), this problem has been fixed in
version 3.8.8-7+squeeze4.

We recommend that you upgrade your request-tracker3.8 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJP0PsjAAoJEL97/wQC1SS+7ecH/jFMGacquBz3fhvbfztCPYEH
DMlxTJLl9yUEOfZM0bXrnmJaTMRS0FVFdQnqJ/APzq6T0Hh4NG8N4H6KhH/8N1PU
uBRO6wVBxZ4Q81c5FZ9MmyXXkqv84j1Se1oqPnZTR9BJ+hFwRF19BzWifMVcE3SC
QzGyUOHJ/r/n52KaQP1YUQli+GZaG7RNlYBY34Zag2vuEXXheQyW++O/830mJvz6
M89FnXazM4NuByEm8wINlq5GkJ2+pYNzx8WWNw7rqzJWPiiqXeFPsTcAnUqHHJlA
aacZTM9prUuUDcZhtvUM+fLCWash5xJtYYNh4bIDSjO2JSJhLr50qLF47yB2yc0=
=CgeJ
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ