-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6485-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff September 06, 2026 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : tryton-server CVE ID : not yet available Two security vulnerabilities were discovered in the server of the Tryton application platform, which could lead to arbitrary command execution via malformed email/report templates. For the stable distribution (trixie), this problem has been fixed in version 7.0.30-1+deb13u2. In addition to the changes in the Tryton server, three modules needed to be updated for compability with the security fix: * tryton-modules-company was updated to 7.0.2-1+deb13u1, * tryton-modules-marketing-automation was updated to 7.0.1-1deb13u1 * tryton-modules-marketing-email was updated to 7.0.0-3deb13u1 We recommend that you upgrade your tryton-server packages. For the detailed security status of tryton-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tryton-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqdSJwACgkQEMKTtsN8 TjaKdA//YgVXJo4vKi38S2R2AVwCmKR33SO/g2LIKoKnWRan/LoWOMkua7EaBhIk GtSUrmMBr04l0Op5PdF7SfSzbvAFvEGyDBrd5xoEo2NaaAFSTuTZmsMTvC4a1EQZ I/zPGfhioPDWHJAkrf1cCC9zN5jeWeU8m0F3MkmIWupZwkPHLjGytrcnAwDDme50 r9WH4EzjW55a8IZUcyuirDdXN53sxiZ8shnxJoy34QMT0+j+LGwTryWrG/gwPfNc 3pu4LWK1aifIEr2CqNj7bAstXVfO8REppv/d4NRP4V3jpB2sAjOPDx6a/uXkS2t5 JXLvQw5OK4TAQ8App0L/kMaJg49ZRmAZ7WP22wvIpYZrIF8NRgKy515mS1MMRk4j totbJgfpHSOKVlxhDMOlLFDBnIB6HQUYONazfaD8Pk7scwKlDGLAqn+jptxXTSHF U/Xh1nGuE0U9IV+bgx7jGXVpvsB7YmX5F65BGCZm3hX2gq4SLvcS+One5AMxuVmQ 2kLrhlx7AkjO3MAks2u/nO98JkeuRiLIpvDmcsEHEyJrCN0Dd3SqfXrA9SbMCDud 6BvULASNBm0XOxQO7B+9hC/7LNiMZux6jWB7TUv0OZJI/MLm09lbWpdMc9Bf9ebn GavSu1IJyKPpzur8sQFOPplzToACB5+1I5JeRTKPVliDtPKsNI0= =Oh3k -----END PGP SIGNATURE-----

