Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.announce.security > #2939 > unrolled thread
| Started by | Moritz Muehlenhoff <jmm@debian.org> |
|---|---|
| First post | 2019-04-07 14:10 +0200 |
| Last post | 2019-04-07 14:10 +0200 |
| Articles | 1 — 1 participant |
Back to article view | Back to linux.debian.announce.security
[SECURITY] [DSA 4426-1] tryton-server security update Moritz Muehlenhoff <jmm@debian.org> - 2019-04-07 14:10 +0200
| From | Moritz Muehlenhoff <jmm@debian.org> |
|---|---|
| Date | 2019-04-07 14:10 +0200 |
| Subject | [SECURITY] [DSA 4426-1] tryton-server security update |
| Message-ID | <xKeMy-Rm-21@gated-at.bofh.it> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4426-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 07, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tryton-server CVE ID : CVE-2019-10868 Cedric Krier discovered that missing access validation in Tryton could result in information disclosure . For the stable distribution (stretch), this problem has been fixed in version 4.2.1-2+deb9u1. We recommend that you upgrade your tryton-server packages. For the detailed security status of tryton-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tryton-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlyp5gsACgkQEMKTtsN8 TjZCjw//W2SCXxV7mPF/sUp1lrvUWXy2OOQTmPLiRRtiIhq8b+1Fdexc0pnmjMyu yx+hd7nT9EvmwKzcxndWEZEBbreoivX202gV5lA+8LM72zKQLpcv+OUf40clVpsr FHrAuMoulHUt+PkQ6NBp4anog17vLxt9Y0vxEyUddFOpsCo20VwHGw4hVo3cyWIw ePmQgUier64SdTnf2qsTkk4eyVhrsTDMd48WjzjfPYlWX6yutmxksEUlmK+OA61U ju1wXM7O40FLTVyIafs4r4cq09siOYLaZv8nYo4we3KXHgOjtvoNoUDc6tBJqY37 i+WcnHtGmgKHOHK9dWBhOacGx0i0pkOaMl1FA4nVqMmYtxd+qReDrdkgkV2i9gSL eIND6AaZRT3Nxc+8s3CZfGMbiN7+18bLdW7ws5qNOUmsq+Hz9x7hz0TLOHRMTNvz yFxYEtUl9OEVq6NaHZo61UiQHkHC/hgNWvuj0xJt52qmhUKS8A/Oi3ATMsfoOPm9 V1MX/pCzuCXTjEZuglIb+jZPF1Lon3d4p0azI8Tf3/oY3L5B4jglfNs/UyXGnWyz A6bTA2NiLIq3V0Uob/bK6pK6ZPaaW0iaf/0Ms4ulswlxkbvVI+GgGoL2IxWaj8K1 BiIunKaqfX+4V5kvNezGbqw07u/vuesN3HYlSqtubqr2WW3Lm/Y= =6Q0H -----END PGP SIGNATURE-----
Back to top | Article view | linux.debian.announce.security
csiph-web