Vulnerability Bulletins

DSA-3883 rt-authen-externalauth - security update

   
Affected software Debian
 
It was discovered that RT::Authen::ExternalAuth, an externalauthentication module for Request Tracker, is vulnerable to timingside-channel attacks for user passwords. Only ExternalAuth in DBI(database) mode is vulnerable.

More info:

https://www.debian.org/security/2017/dsa-3883