DSA-1937-1

NameDSA-1937-1
SourceDebian
Descriptiongforge - cross-site scripting
ReferencesCVE-2009-3303
Debian/oldstablepackage gforge is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gforge (PTS)etch4.5.14-22etch10vulnerable
etch (security)4.5.14-22etch13fixed
lenny, lenny (security)4.7~rc2-7lenny3fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-ldap-openldap, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim, gforge-mta-exim4, gforge-mta-postfix, gforge-shell-ldap, gforge-shell-postgresql, gforge-web-apacheetch4.5.14-22etch10vulnerableall
etch (security)4.5.14-22etch13fixedall
gforge, gforge-common, gforge-db-postgresql, gforge-dns-bind9, gforge-ftp-proftpd, gforge-lists-mailman, gforge-mta-courier, gforge-mta-exim4, gforge-mta-postfix, gforge-plugin-mediawiki, gforge-plugin-scmcvs, gforge-plugin-scmsvn, gforge-shell-postgresql, gforge-web-apache, gforge-web-apache2lenny, lenny (security)4.7~rc2-7lenny3fixedall

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gforgesourceetch4.5.14-22etch12unknown
gforgesourcelenny4.7~rc2-7lenny2unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint