Oval Definition:oval:org.mitre.oval:def:13368
Revision Date:2014-06-23Version:20
Title:DSA-1990-2 trac-git -- shell command injection
Description:The trac-git package released in DSA-1990-1 had a wrong dependency that could not be satisfied in Debian stable. This update corrects this problem. For reference, the original advisory text is provided below. Stefan Goebel discovered that the Debian version of trac-git, the Git add-on for the Trac issue tracking system, contains a flaw which enables attackers to execute code on the web server running trac-git by sending crafted HTTP queries. The old stable distribution does not contain a trac-git package. For the stable distribution, this problem has been fixed in version 0.0.20080710-3+lenny2. For the unstable distribution and the testing distribution, this problem has been fixed in version 0.0.20090320-1.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-0394
DSA-1990-2
Platform(s):Debian GNU/Linux 5.0
Product(s):trac-git
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Installed architecture is all
  • AND trac-git DPKG is earlier than 0.0.20080710-3+lenny2
  • BACK