CVE-2014-0468

NameCVE-2014-0468
DescriptionVulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in their raw SCM repositories (SVN, Git, Bzr...). This issue affects fusionforge: before 5.3+20140506.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
fusionforgesourcesqueeze(unfixed)end-of-life
fusionforgesource(unstable)5.3+20140506-1

Notes

[squeeze] - fusionforge <end-of-life> (Unsupported in squeeze-lts)
http://lists.fusionforge.org/pipermail/fusionforge-general/2014-March/002645.html

Search for package or bug name: Reporting problems