[gforge] [CVE-2008-0173] SQL injection vulnerability

Bug #182809 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
gforge (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: gforge

References:
DSA-1459-1 (http://www.debian.org/security/2008/dsa-1459)

Quoting:
"It was discovered that Gforge, a collaborative development tool, did not
properly sanitise some CGI parameters, allowing SQL injection in scripts
related to RSS exports."

CVE References

Revision history for this message
Michael Bienia (geser) wrote :

For hardy fixed in gforge 4.6.99+svn6330-1.

Daniel T Chen (crimsun)
Changed in gforge:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.