request-tracker4 4.4.4+dfsg-2ubuntu1.23.10.1 source package in Ubuntu

Changelog

request-tracker4 (4.4.4+dfsg-2ubuntu1.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: Cross-Site Scripting
    - debian/patches/upstream_4.4.4_cve:_patchset_2022-06-29.diff: fixed an XSS
      in request-tracker (CVE-2022-25802)
    - CVE-2022-25802
  * SECURITY UPDATE: Information Leakage and Unvalidated Headers
    - debian/patches/upstream_4.4-trunk_cve:_avoid_time_side_channel_attack.diff:
      fixed an issue that was resulting in leaking sensitive information
      (CVE-2021-38562)
    - debian/patches/upstream_4.4.3_cve:_patchset_2023-09-26.diff: fixed an
      issue with unvalidated email headers (CVE-2023-41259) and an information
      leakage (CVE-2023-41260) in request-tracker
    - debian/patches/upstream_4.4.3_cve:_patchset_2023-09-26-tests.diff: added
      tests for patches for CVE-2023-41259 and CVE-2023-41260
    - debian/patches/fix_expired_certs.diff: fixes related tests
    - CVE-2021-38562
    - CVE-2023-41259
    - CVE-2023-41260
  * debian/patches/fix_ftbfs.patch: fixex a FTBFS in mantic
  * debian/patches/Update-tests-for-EN-datetime-locale-change-to-space.diff:
    updated broken tests
  * debian/patches/Switch-to-Test-MockTime-HiRes-in-date-api-test.diff: added
    required dependencies
  * debian/patches/update-legacy-timezones.patch: fixed outdated tests
  * debian/control: added the required build dependency

 -- Amir Naseredini <email address hidden>  Thu, 30 Nov 2023 12:26:43 +0000

Upload details

Uploaded by:
Amir Naseredini
Uploaded to:
Mantic
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Mantic updates universe misc
Mantic security universe misc

Builds

Mantic: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
request-tracker4_4.4.4+dfsg.orig-third-party-source.tar.gz 3.0 MiB 9f142a07b09cd34c9120fa71b88fab7904bdb475096ac7405766d7ca2ee3505d
request-tracker4_4.4.4+dfsg.orig.tar.gz 9.5 MiB 34c316a4a78d7ee9b95d4391530f9bb3ff3edd99ebbebfac6354ed173e940884
request-tracker4_4.4.4+dfsg-2ubuntu1.23.10.1.debian.tar.xz 151.1 KiB 84297cab6d343399157ec79039f383245e969d90a3ceb17c7c246d8866856003
request-tracker4_4.4.4+dfsg-2ubuntu1.23.10.1.dsc 5.4 KiB a8f37a98eeed0f0ff107f90a295eb8fb8e37e361fed8c77e881f3fa628ebd849

View changes file

Binary packages built by this source

request-tracker4: extensible trouble-ticket tracking system

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This package provides the core of RT.
 .
 This package supports three database types out of the box: MySQL,
 PostgreSQL and SQLite. In order to support a zero-configuration install,
 SQLite will be used by default, but is not recommended for production
 use. Please see /usr/share/doc/request-tracker4/NOTES.Debian for more
 details and consider installing rt4-db-postgresql or rt4-db-mysql at
 the same time as this package.

rt4-apache2: Apache 2 specific files for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This package provides various configuration files and manages the
 necessary dependencies for running request tracker (RT) version 4
 on the Apache 2 web server.

rt4-clients: mail gateway and command-line interface to request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This package provides support for injecting tickets into Request Tracker
 from a mail server via rt-mailgate. It may be installed onto any
 machine where you want to use the "rt" command-line interface.

rt4-db-mysql: MySQL database backend for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This empty package provides dependencies and dbconfig-common support for
 using Request Tracker version 4 with a MySQL database.

rt4-db-postgresql: PostgreSQL database backend for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This empty package provides dependencies and dbconfig-common support for
 using Request Tracker version 4 with a PostgreSQL database.

rt4-db-sqlite: SQLite database backend for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This empty package provides dependencies and dbconfig-common support for
 using Request Tracker version 4 with a local SQLite (version 3) database.
 .
 This package will be pulled in by default by request-tracker4, but SQLite
 is not recommended for production use. Please see
 /usr/share/doc/request-tracker4/NOTES.Debian for more details and
 consider installing rt4-db-postgresql or rt4-db-mysql instead of this
 package.

rt4-doc-html: HTML documentation for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This package provides HTML documentation for RT.

rt4-fcgi: External FastCGI support for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This package provides an external FCGI interface for web servers
 including, but not limited to, nginx, and is not needed for web servers
 such as Apache which invoke FCGI programs directly.

rt4-standalone: Standalone web server support for request-tracker4

 Request Tracker (RT) is a ticketing system which
 enables a group of people to intelligently and efficiently manage
 tasks, issues, and requests submitted by a community of users. It
 features web, email, and command-line interfaces (see the package
 rt4-clients).
 .
 RT manages key tasks such as the identification, prioritization,
 assignment, resolution, and notification required by
 enterprise-critical applications, including project management, help
 desk, NOC ticketing, CRM, and software development.
 .
 This package provides the 4 series of RT. It can be installed alongside
 the 3.8 series without any problems.
 .
 This metapackage provides the standalone web server interface.