CVE-2008-2381

NameCVE-2008-2381
SourceCVE (at NVD; RH)
DescriptionSQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
ReferencesDSA-1698-1
NVD severityhigh
Debian/oldstablenot vulnerable
Debian/stablenot vulnerable
Debian/testingnot vulnerable
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gforge (PTS)etch4.5.14-22etch10fixed
etch (security)4.5.14-22etch13fixed
lenny, lenny (security)4.7~rc2-7lenny3fixed
squeeze4.8.2-1fixed
sid4.8.2-2fixed
experimental4.8.55+svn8699-1fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-ldap-openldap, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim, gforge-mta-exim4, gforge-mta-postfix, gforge-shell-ldap, gforge-shell-postgresql, gforge-web-apacheetch4.5.14-22etch10fixedall
etch (security)4.5.14-22etch13fixedall
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim4, gforge-mta-postfix, gforge-plugin-contribtracker, gforge-plugin-extratabs, gforge-plugin-globalsearch, gforge-plugin-mediawiki, gforge-plugin-projectlabels, gforge-plugin-scmarch, gforge-plugin-scmbzr, gforge-plugin-scmcvs, gforge-plugin-scmdarcs, gforge-plugin-scmgit, gforge-plugin-scmhg, gforge-plugin-scmsvn, gforge-shell-postgresql, gforge-web-apache, gforge-web-apache2experimental4.8.55+svn8699-1fixedall
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim4, gforge-mta-postfix, gforge-plugin-mediawiki, gforge-plugin-scmcvs, gforge-plugin-scmsvn, gforge-shell-postgresql, gforge-web-apache, gforge-web-apache2lenny, lenny (security)4.7~rc2-7lenny3fixedall
squeeze4.8.1-2fixedall
squeeze4.8.2-1fixedall
sid4.8.2-2fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gforgesource(unstable)4.7~rc2-7unknown
gforgesourceetch4.5.14-22etch10unknownDSA-1698-1

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint