Debian DSA-4191-1 : redmine - security update

high Nessus Plugin ID 109558

Synopsis

The remote Debian host is missing a security-related update.

Description

Multiple vulnerabilities were discovered in Redmine, a project management web application. They could lead to remote code execution, information disclosure or cross-site scripting attacks.

Solution

Upgrade the redmine packages.

For the stable distribution (stretch), these problems have been fixed in version 3.3.1-4+deb9u1.

In addition, this message serves as an announcement that security support for redmine in the Debian 8 oldstable release (jessie) is now discontinued.

Users of redmine in Debian 8 that want security updates are strongly encouraged to upgrade now to the current Debian 9 stable release (stretch).

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882544

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882545

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882547

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882548

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887307

https://security-tracker.debian.org/tracker/source-package/redmine

https://packages.debian.org/source/stretch/redmine

https://www.debian.org/security/2018/dsa-4191

Plugin Details

Severity: High

ID: 109558

File Name: debian_DSA-4191.nasl

Version: 1.5

Type: local

Agent: unix

Published: 5/4/2018

Updated: 10/14/2024

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-15575

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2017-18026

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:redmine, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 5/3/2018

Reference Information

CVE: CVE-2017-15568, CVE-2017-15569, CVE-2017-15570, CVE-2017-15571, CVE-2017-15572, CVE-2017-15573, CVE-2017-15574, CVE-2017-15575, CVE-2017-15576, CVE-2017-15577, CVE-2017-16804, CVE-2017-18026

DSA: 4191