RT 1.0.4 is now available at
It is recommended that you upgrade to this release as soon as
is reasonably possible, as it closes a possible security hole
in rt-mailgate which could allow an attacker to resolve arbitrary
tickets. I’d like to thank Michael J. Pomraning from SecurePipe
for bringing this to my attention and for professionally handling the
report of the hole. Expect a full advisory with explanation
within several days.
Additionally, rt-mailgate got an overhaul sponsored by MAPS LLC.
To see the new options available, run rt-mailgate --help. Mailgate
will continue to work as you expect it to unless you use the
–extended-syntax flag when invoking it.
New installations will get the benefit of a 25 character phone
field in user records. (Compared to 1.0.3’s 15 characters)
A couple permissions nits were fixed in the makefile.
If you experience any issues with the upgrade to or installation of
RT 1.0.4, please don’t hesitate to contact firstname.lastname@example.org
Thanks, Jesse Vincent