Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.announce.security > #2939
| Path | csiph.com!weretis.net!feeder7.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Moritz Muehlenhoff <jmm@debian.org> |
| Newsgroups | linux.debian.announce.security |
| Subject | [SECURITY] [DSA 4426-1] tryton-server security update |
| Date | Sun, 07 Apr 2019 14:10:02 +0200 |
| Message-ID | <xKeMy-Rm-21@gated-at.bofh.it> (permalink) |
| X-Mailbox-Line | From debian-security-announce-request@lists.debian.org Sun Apr 7 12:01:09 2019 |
| Old-Return-Path | <jmm@seger.debian.org> |
| X-Amavis-Spam-Status | No, score=-13.28 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| User-Agent | NeoMutt/20170113 (1.7.2) |
| X-Debian | PGP check passed for security officers |
| Priority | urgent |
| Reply-To | debian-security-announce-request@lists.debian.org |
| X-Mailing-List | <debian-security-announce@lists.debian.org> archive/latest/3295 |
| List-ID | <debian-security-announce.lists.debian.org> |
| List-URL | <http://lists.debian.org/debian-security-announce/> |
| List-Archive | https://lists.debian.org/msgid-search/20190407120053.rqcmzl4zmwkdqfpx@seger.debian.org |
| Approved | robomod@news.nic.it |
| Lines | 45 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Sun, 7 Apr 2019 12:00:53 +0000 |
| X-Original-Message-ID | <20190407120053.rqcmzl4zmwkdqfpx@seger.debian.org> |
| Xref | csiph.com linux.debian.announce.security:2939 |
Show key headers only | View raw
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4426-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 07, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tryton-server CVE ID : CVE-2019-10868 Cedric Krier discovered that missing access validation in Tryton could result in information disclosure . For the stable distribution (stretch), this problem has been fixed in version 4.2.1-2+deb9u1. We recommend that you upgrade your tryton-server packages. For the detailed security status of tryton-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tryton-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlyp5gsACgkQEMKTtsN8 TjZCjw//W2SCXxV7mPF/sUp1lrvUWXy2OOQTmPLiRRtiIhq8b+1Fdexc0pnmjMyu yx+hd7nT9EvmwKzcxndWEZEBbreoivX202gV5lA+8LM72zKQLpcv+OUf40clVpsr FHrAuMoulHUt+PkQ6NBp4anog17vLxt9Y0vxEyUddFOpsCo20VwHGw4hVo3cyWIw ePmQgUier64SdTnf2qsTkk4eyVhrsTDMd48WjzjfPYlWX6yutmxksEUlmK+OA61U ju1wXM7O40FLTVyIafs4r4cq09siOYLaZv8nYo4we3KXHgOjtvoNoUDc6tBJqY37 i+WcnHtGmgKHOHK9dWBhOacGx0i0pkOaMl1FA4nVqMmYtxd+qReDrdkgkV2i9gSL eIND6AaZRT3Nxc+8s3CZfGMbiN7+18bLdW7ws5qNOUmsq+Hz9x7hz0TLOHRMTNvz yFxYEtUl9OEVq6NaHZo61UiQHkHC/hgNWvuj0xJt52qmhUKS8A/Oi3ATMsfoOPm9 V1MX/pCzuCXTjEZuglIb+jZPF1Lon3d4p0azI8Tf3/oY3L5B4jglfNs/UyXGnWyz A6bTA2NiLIq3V0Uob/bK6pK6ZPaaW0iaf/0Ms4ulswlxkbvVI+GgGoL2IxWaj8K1 BiIunKaqfX+4V5kvNezGbqw07u/vuesN3HYlSqtubqr2WW3Lm/Y= =6Q0H -----END PGP SIGNATURE-----
Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread
[SECURITY] [DSA 4426-1] tryton-server security update Moritz Muehlenhoff <jmm@debian.org> - 2019-04-07 14:10 +0200
csiph-web