DSA-3656-1 tryton-server -- security update

Related Vulnerabilities: CVE-2016-1241   CVE-2016-1242  

Two vulnerabilities have been discovered in the server for the Tryton application platform, which may result in information disclosure of password hashes or file contents. For the stable distribution (jessie), these problems have been fixed in version 3.4.0-3+deb8u2. For the unstable distribution (sid), these problems have been fixed in version 4.0.4-1. We recommend that you upgrade your tryton-server packages.

Debian Security Advisory

DSA-3656-1 tryton-server -- security update

Date Reported:
30 Aug 2016
Affected Packages:
tryton-server
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-1241, CVE-2016-1242.
More information:

Two vulnerabilities have been discovered in the server for the Tryton application platform, which may result in information disclosure of password hashes or file contents.

For the stable distribution (jessie), these problems have been fixed in version 3.4.0-3+deb8u2.

For the unstable distribution (sid), these problems have been fixed in version 4.0.4-1.

We recommend that you upgrade your tryton-server packages.