Описание
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| request-tracker4 | fixed | 4.2.11-2 | package | |
| request-tracker4 | fixed | 4.2.8-3+deb8u1 | jessie | package |
| request-tracker4 | not-affected | wheezy | package |
Примечания
https://github.com/bestpractical/rt/commit/36a461947b00b105336adb4997d1c7767d8484c4
https://www.openwall.com/lists/oss-security/2015/08/13/8
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.