Summary
The remote host is missing an update to trac
announced via advisory DSA 1209-2.
The Trac update in DSA 1209 introduced a regression. This update corrects this flaw. For completeness, the original advisory text below:
It was discovered that Trac, a wiki and issue tracking system for software development projects, performs insufficient validation against cross-site request forgery, which might lead to an attacker being able to perform manipulation of a Trac site with the privileges of the attacked Trac user.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.8.1-3sarge6.
For the unstable distribution (sid) this problem has been fixed in version 0.10.1-1.
We recommend that you upgrade your trac package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201209-2
Severity
Classification
-
CVE CVE-2006-5878 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities