CVE-2008-0173
| Name | CVE-2008-0173 |
| Source | CVE (at NVD; RH) |
| Description | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports. |
| References | DSA-1459-1 |
| NVD severity | high (attack range: remote) |
| Debian/oldstable | not vulnerable. |
| Debian/stable | not known to be vulnerable. |
| Debian/testing | not known to be vulnerable. |
| Debian/unstable | not known to be vulnerable. |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| gforge (PTS) | lenny, lenny (security) | 4.7~rc2-7lenny3 | fixed |
The information above is based on the following data on fixed versions.
Notes
this is exploitable by unauthenticated users
Requires register_globals to be On, unsupported in lenny+sid.
In lenny+sid these scripts just don't work, so no security issue.
In etch+sarge we support gforge with rg On, unfortunately.
Home - Testing Security Team - Debian Security - Imprint