Trac 0.8 has known security holes; please rebuild 0.8.4

Bug #1559 reported by chastell
10
Affects Status Importance Assigned to Milestone
trac (Ubuntu)
Fix Released
Medium
MOTU
Hoary
Fix Released
Medium
MOTU
Breezy
Fix Released
Medium
MOTU

Bug Description

The current Trac version in Ubuntu (0.8-1ubuntu1) has a known security vulnerability[1]. Please rebuild trac 0.8.4-1 from Debian for Breezy and port the changes back to Hoary if possible.

[1] http://projects.edgewall.com/trac/wiki/ChangeLog

CVE References

chastell (chastell)
description: updated
Revision history for this message
japj (japj) wrote :

Please also note that the latest 0.8.1 in debian is 0.8.1-3sarge2 release which contains security patches for this specific security vulnerability. Maybe this security patch can be backported to ubuntu (if upgrading to 0.8.4 is too big a step).

Changed in trac:
assignee: nobody → motu
assignee: nobody → motu
assignee: nobody → motu
Trent Lloyd (lathiat)
Changed in trac:
status: New → Fixed
Revision history for this message
Trent Lloyd (lathiat) wrote :

Thanks for the report Shot.

This is fixed in Ubuntu Breezy with 0.8.4, I have prepared and submitted a hoary security upload with the fix, pending review.

Changed in trac:
status: New → Accepted
status: New → Accepted
Revision history for this message
Hervé Cauwelier (hcauwelier-deactivatedaccount) wrote :

It seems like it didn't make it in Hoary. Martin? Trent?

Revision history for this message
Trent Lloyd (lathiat) wrote :

Sorry, this was actually fixed and uploaded to hoary-security

http://changelogs.ubuntu.com/changelogs/pool/universe/t/trac/trac_0.8-1ubuntu1.1/changelog

Changed in trac:
status: Accepted → Fixed
Lukas Fittl (lfittl)
Changed in trac:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.