Summary
The remote host is missing an update to trac
announced via advisory DSA 1209-1.
It was discovered that Trac, a wiki and issue tracking system for software development projects, performs insufficient validation against cross-site request forgery, which might lead to an attacker being able to perform manipulation of a Trac site with the privileges of the attacked Trac user.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.8.1-3sarge6.
For the unstable distribution (sid) this problem has been fixed in version 0.10.1-1.
We recommend that you upgrade your trac package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201209-1
Severity
Classification
-
CVE CVE-2006-5878 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities