CVE-2008-0173

NameCVE-2008-0173
SourceCVE (in NVD)
DescriptionSQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.
ReferencesDSA-1459-1
NVD severityhigh
Debian/stablenot vulnerable
Debian/testingnot vulnerable
Debian/unstablenot vulnerable

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gforge (PTS)etch, etch (security)4.5.14-22etch8fixed
lenny, sid4.7~rc2-6fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-ldap-openldap, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim, gforge-mta-exim4, gforge-mta-postfix, gforge-shell-ldap, gforge-shell-postgresql, gforge-web-apacheetch, etch (security)4.5.14-22etch8fixedall
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim4, gforge-mta-postfix, gforge-plugin-mediawiki, gforge-plugin-scmcvs, gforge-plugin-scmsvn, gforge-shell-postgresql, gforge-web-apache, gforge-web-apache2lenny, sid4.7~rc2-6fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gforgesource(unstable)4.6.99+svn6330-1medium
gforgesourceetch4.5.14-22etch4unknownDSA-1459-1
gforgesourcesarge3.1-31sarge5unknownDSA-1459-1

Notes

this is exploitable by unauthenticated users
Requires register_globals to be On, unsupported in lenny+sid.
In lenny+sid these scripts just don't work, so no security issue.
In etch+sarge we support gforge with rg On, unfortunately.

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint