Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
{
"binaries": [
{
"binary_name": "request-tracker4",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-apache2",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-clients",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-db-mysql",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-db-postgresql",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-db-sqlite",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-doc-html",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-fcgi",
"binary_version": "4.2.12-5"
},
{
"binary_name": "rt4-standalone",
"binary_version": "4.2.12-5"
}
]
}{
"binaries": [
{
"binary_name": "request-tracker4",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-apache2",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-clients",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-db-mysql",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-db-postgresql",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-db-sqlite",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-doc-html",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-fcgi",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
},
{
"binary_name": "rt4-standalone",
"binary_version": "4.4.3-2+deb10u3build0.20.04.1"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "request-tracker4",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-apache2",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-clients",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-db-mysql",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-db-postgresql",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-db-sqlite",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-doc-html",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-fcgi",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
},
{
"binary_name": "rt4-standalone",
"binary_version": "4.4.4+dfsg-2ubuntu1.22.04.1"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "request-tracker4",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-apache2",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-clients",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-db-mysql",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-db-postgresql",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-db-sqlite",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-doc-html",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-fcgi",
"binary_version": "4.4.4+dfsg-2ubuntu2"
},
{
"binary_name": "rt4-standalone",
"binary_version": "4.4.4+dfsg-2ubuntu2"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_name": "request-tracker4",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-apache2",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-clients",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-db-mysql",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-db-postgresql",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-db-sqlite",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-doc-html",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-fcgi",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
},
{
"binary_name": "rt4-standalone",
"binary_version": "4.4.2-2ubuntu0.1~esm1"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_name": "request-tracker5",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-apache2",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-clients",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-mysql",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-postgresql",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-db-sqlite",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-doc-html",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-fcgi",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
},
{
"binary_name": "rt5-standalone",
"binary_version": "5.0.1+dfsg-1ubuntu1+esm1"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}