CVE-2021-38562

NameCVE-2021-38562
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs995167, 995175

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
request-tracker4 (PTS)stretch4.4.1-3+deb9u3vulnerable
stretch (security)4.4.1-3+deb9u1vulnerable
buster4.4.3-2+deb10u1fixed
bullseye4.4.4+dfsg-2+deb11u1fixed
bookworm, sid4.4.4+dfsg-3fixed
request-tracker5 (PTS)sid5.0.1+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
request-tracker4sourcebuster4.4.3-2+deb10u1
request-tracker4sourcebullseye4.4.4+dfsg-2+deb11u1
request-tracker4source(unstable)4.4.4+dfsg-3995175
request-tracker5source(unstable)(unfixed)995167

Notes

[stretch] - request-tracker4 <no-dsa> (Minor issue)
https://github.com/bestpractical/rt/commit/70749bb66cb13dd70bd53340c371038a5f3ca57c (rt-5.0.2)
https://github.com/bestpractical/rt/commit/d16f8cf13c2af517ee55a85e7b91a0267477189f (rt-4.4.5)
https://github.com/bestpractical/rt/commit/d16f8cf13c2af517ee55a85e7b91a0267477189f (rt-4.2.17)

Search for package or bug name: Reporting problems