"-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- ------------------------------------------------------------------------
Debian Security Advisory DSA-1990-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
February 03, 2010 http://www.debian.org/security/faq
- ------------------------------------------------------------------------
Package : trac-git
Vulnerability : shell command injection
Problem type : remote
Debian-specific: yes
CVE Id(s) : CVE-2010-0394
Debian Bug : 567039
Stefan Goebel discovered that the Debian version of trac-git, the Git
add-on for the Trac issue tracking system, contains a flaw which
enables attackers to execute code on the web server running trac-git
by sending crafted HTTP queries.
The old stable distribution (etch) does not contain a trac-git package.
For the stable distribution (lenny), this problem has been fixed in
version 0.0.20080710-3+lenny1.
For the unstable distribution (sid) and the testing distribution
(squeeze), this problem has been fixed in version 0.0.20090320-1.
We recommend that you upgrade your trac-git package.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 5.0 alias lenny
- --------------------------------
Source archives:
http://security.debian.org/pool/updates/main/t/trac-git/trac-git_0.0.20080710-3+lenny1.dsc
Size/MD5 checksum: 1312 4357cd66c8df3ac03273f9f858d14928
http://security.debian.org/pool/updates/main/t/trac-git/trac-git_0.0.20080710-3+lenny1.diff.gz
Size/MD5 checksum: 4262 af5bbdd092dfe8d953bcb2183c1228c4
http://security.debian.org/pool/updates/main/t/trac-git/trac-git_0.0.20080710.orig.tar.gz
Size/MD5 checksum: 28505 c8220478c501b7ab3e6df97cea6d2e26
Architecture independent packages:
http://security.debian.org/pool/updates/main/t/trac-git/trac-git_0.0.20080710-3+lenny1_all.deb
Size/MD5 checksum: 16920 d91bf3dc4b15e1c999f7dc5e65e0de65
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show ' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iQEcBAEBAgAGBQJLafM5AAoJEL97/wQC1SS+ChkH/i8B9Iij86LWyp7vd8QI+XJb
bgVkrtty7VjM/zjDGaPm3M6L6TeQLVVDzbVVPcZ3GkZO3sP5S+hqc5tc6der9soy
fVtV44BIIydu8u0bDQIZD44k/mC6YzwATy7rxDLz0VAblUYmgMvlPWWbRE5TIR/e
i+8bdqc7dEab0aBLNy3TwnytsVIpWZfaBOK7M49P131FV3j5W15GjYtlzP1PmyVn
0DhLrPB3KQ0l8XwdW3iSjMsWDcl3TlO7i1X6H9Ef7CXuWVYx7NDwbBnGRwx77sJB
y6PI+cXRwWLHI89Dj8LUnS4KVZ+7Kgd5ALleJvhLy6W+WswanKjotafIeLB8Ems=
=TLBg
-----END PGP SIGNATURE-----
"
DSA 1982-1: New hybserv packages fix denial of serviceVictoria fumes as David Beckham has his balls grabbed
This entry was posted
on 5:49 AM
.
Archives
-
▼
2010
(391)
-
▼
February
(42)
- USN-905-1: sudo vulnerabilities
- RHSA-2010:0115-01 Moderate: pidgin security update
- RHSA-2010:0122-01 Important: sudo security update
- USN-904-1: Squid vulnerability
- DSA 2003-1: New Linux 2.6.18 packages fix several ...
- DSA-2002-1: New polipo packages fix denial of service
- RHSA-2010:0114-01 Critical: acroread security and ...
- USN-902-1: Pidgin vulnerabilities
- DSA 1999-1: New xulrunner packages fix several vul...
- USN-895-1: Firefox 3.0 and Xulrunner 1.9 vulnerabi...
- USN-890-5: XML-RPC for C and C++ vulnerabilities
- DSA 2000-1: New ffmpeg packages fix several vulner...
- RHSA-2010:0110-01 Moderate: mysql security update
- RHSA-2010:0115-01 Moderate: pidgin security update
- USN-896-1: Firefox 3.5 and Xulrunner 1.9.1 vulnera...
- RHSA-2010:0112-01 Critical: firefox security update
- RHSA-2010:0113-01 Critical: seamonkey security update
- DSA 1998-1: New kdelibs packages fix arbitrary cod...
- RHSA-2010:0108-01 Moderate: NetworkManager securit...
- USN-900-1: Ruby vulnerabilities
- USN-898-1: gnome-screensaver vulnerability
- RHSA-2010:0103-01 Important: flash-plugin security...
- DSA-1997-1: New mysql-dfsg-5.0 packages fix severa...
- DSA 1994-1: New ajaxterm packages fix session hija...
- RHSA-2010:0102-01 Important: flash-plugin security...
- USN-897-1: MySQL vulnerabilities
- USN-899-1: Tomcat vulnerabilities
- DSA 1992-1: New chrony packages fix denial of service
- DSA 1993-1: New otrs2 packages fix SQL injection
- RHSA-2010:0094-02 Critical: HelixPlayer security u...
- RHSA-2010:0079-01 Important: kernel security and b...
- DSA 1986-1: New moodle packages fix several vulner...
- DSA 1991-1: New squid/squid3 packages fix denial o...
- RHSA-2010:0088-02 Important: kvm security and bug ...
- DSA-1989-1: New fuse packages fix denial of service
- DSA 1841-2: New git-core packages fix build failure
- DSA 1987-1: New lighttpd packages fix denial of se...
- DSA 1983-1: New Wireshark packages fix several vul...
- DSA-1990-2: New trac-git package fixes regression
- DSA-1990-1: New trac-git packages fix code execution
- DSA 1982-1: New hybserv packages fix denial of ser...
- DSA 1968-2: New pdns-recursor packages fix cache p...
-
▼
February
(42)