UBUNTU-CVE-2013-3525

Source
https://ubuntu.com/security/CVE-2013-3525
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-3525.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-3525
Upstream
  • CVE-2013-3525
Withdrawn
2025-07-18T16:42:54Z
Published
2013-05-10T21:55:00Z
Modified
2025-07-16T08:10:44.850486Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

** DISPUTED ** SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims."

References

Affected packages

Ubuntu:14.04:LTS / request-tracker4

Package

Name
request-tracker4
Purl
pkg:deb/ubuntu/request-tracker4@4.0.19-1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.19-1

Affected versions

4.*
4.0.13-1
4.0.18-1
4.0.18-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "request-tracker4",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-apache2",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-clients",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-db-mysql",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-db-postgresql",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-db-sqlite",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-doc-html",
            "binary_version": "4.0.19-1"
        },
        {
            "binary_name": "rt4-fcgi",
            "binary_version": "4.0.19-1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-3525.json"