Debian: New gforge packages fix SQL injection

    Date 13 Jan 2008
    2723
    Posted By LinuxSecurity Advisories
    It was discovered that Gforge, a collaborative development tool, did not properly sanitise some CGI parameters, allowing SQL injection in scripts related to RSS exports.
    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-1459-1                  This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.debian.org/security/                          Thijs Kinkhorst
    January 13, 2008                      https://www.debian.org/security/faq
    - ------------------------------------------------------------------------
    
    Package        : gforge
    Vulnerability  : insufficient input validation
    Problem-Type   : remote
    Debian-specific: no
    CVE ID         : CVE-2008-0173
    
    It was discovered that Gforge, a collaborative development tool, did not
    properly sanitise some CGI parameters, allowing SQL injection in scripts
    related to RSS exports.
    
    For the stable distribution (etch), this problem has been fixed in
    version 4.5.14-22etch4.
    
    For the old stable distribution (sarge), this problem has been fixed in
    version 3.1-31sarge5.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 4.6.99+svn6330-1.
    
    We recommend that you upgrade your gforge packages.
    
    Upgrade instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    
    Debian 3.1 (oldstable)
    - ----------------------
    
    Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      https://security.debian.org/pool/updates/main/g/gforge/gforge_3.1-31sarge5.diff.gz
        Size/MD5 checksum:   298148 fd78915a83bd2c0ebf907adb10369846
      https://security.debian.org/pool/updates/main/g/gforge/gforge_3.1.orig.tar.gz
        Size/MD5 checksum:  1409879 c723b3a9efc016fd5449c4765d5de29c
      https://security.debian.org/pool/updates/main/g/gforge/gforge_3.1-31sarge5.dsc
        Size/MD5 checksum:      868 336e19234bd80dd1856259700146978a
    
    Architecture independent packages:
    
      https://security.debian.org/pool/updates/main/g/gforge/gforge-web-apache_3.1-31sarge5_all.deb
        Size/MD5 checksum:  1108124 36e222e23527c67affc8d103bc483351
      https://security.debian.org/pool/updates/main/g/gforge/gforge-lists-mailman_3.1-31sarge5_all.deb
        Size/MD5 checksum:    58324 639ec6b4b363a4526d6d459858b230ce
      https://security.debian.org/pool/updates/main/g/gforge/gforge-ftp-proftpd_3.1-31sarge5_all.deb
        Size/MD5 checksum:    59936 1201c29fe43d659ba1fa1ec8d1c97dcb
      https://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_3.1-31sarge5_all.deb
        Size/MD5 checksum:   148510 c4eeb3e6b1fb6d1d5d8b7a5dcbdc2b5a
      https://security.debian.org/pool/updates/main/g/gforge/gforge-common_3.1-31sarge5_all.deb
        Size/MD5 checksum:    93948 8b3b2651d9c87db5001a3207174f0620
      https://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_3.1-31sarge5_all.deb
        Size/MD5 checksum:    72540 3c46ebf2c9c7790913b4138fda70abf7
      https://security.debian.org/pool/updates/main/g/gforge/gforge_3.1-31sarge5_all.deb
        Size/MD5 checksum:    56466 2b16eefa372e82788db9d8628f689763
      https://security.debian.org/pool/updates/main/g/gforge/gforge-cvs_3.1-31sarge5_all.deb
        Size/MD5 checksum:    99274 63cd91f21d6c1c8070cab36e8c116b57
      https://security.debian.org/pool/updates/main/g/gforge/gforge-sourceforge-transition_3.1-31sarge5_all.deb
        Size/MD5 checksum:    59412 6ad709e90b0071acf6b002824c99a996
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim_3.1-31sarge5_all.deb
        Size/MD5 checksum:    64758 552a93aa07b144e643dfbcc97cb84064
      https://security.debian.org/pool/updates/main/g/gforge/sourceforge_3.1-31sarge5_all.deb
        Size/MD5 checksum:    55908 bfc08b5a188699a7b524ca8849d123db
      https://security.debian.org/pool/updates/main/g/gforge/gforge-ldap-openldap_3.1-31sarge5_all.deb
        Size/MD5 checksum:    70838 f699bb5444a9b7bb8e096c44e3cd0650
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_3.1-31sarge5_all.deb
        Size/MD5 checksum:    64858 efd816ced0348fa8b56f4c3e5256a840
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim4_3.1-31sarge5_all.deb
        Size/MD5 checksum:    65220 b9e32d3ccfa6a1de77393da4563e5fb2
      https://security.debian.org/pool/updates/main/g/gforge/gforge-shell-ldap_3.1-31sarge5_all.deb
        Size/MD5 checksum:    61078 3374d78c0cef648a6aad1725a1e6cb1a
    
    Debian 4.0 (stable)
    - -------------------
    
    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.
    
    Source archives:
    
      https://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14.orig.tar.gz
        Size/MD5 checksum:  2161141 e85f82eff84ee073f80a2a52dd32c8a5
      https://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch4.diff.gz
        Size/MD5 checksum:   197311 a00eedb23b776476b9a42618487d89b1
      https://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch4.dsc
        Size/MD5 checksum:      950 b36ce450f342c604fd12549450fff6ae
    
    Architecture independent packages:
    
      https://security.debian.org/pool/updates/main/g/gforge/gforge-dns-bind9_4.5.14-22etch4_all.deb
        Size/MD5 checksum:   103548 beacacca088438618b23477f568f08e0
      https://security.debian.org/pool/updates/main/g/gforge/gforge-ldap-openldap_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    95388 aa8716e4240606526fc633ba8c02b74a
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-courier_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    75870 81c7219391d9fac23d6df62be3ab8bf5
      https://security.debian.org/pool/updates/main/g/gforge/gforge-db-postgresql_4.5.14-22etch4_all.deb
        Size/MD5 checksum:   212334 4cc28fdcf336a60bba2a89072683a5f9
      https://security.debian.org/pool/updates/main/g/gforge/gforge-shell-postgresql_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    86934 ea3e49b38459636b14ba4346bc045cf0
      https://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    80056 fb3df49a34571c38a43e625e73f1a124
      https://security.debian.org/pool/updates/main/g/gforge/gforge-ftp-proftpd_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    85838 4f38f483e13b4c9b5fcbbd379ff841f4
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    88404 ba2c15b2bdd2f67a8abd3dd0bf9a326e
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-exim4_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    88914 0e657fdc22f4e1f14a63e3c583bc2dcb
      https://security.debian.org/pool/updates/main/g/gforge/gforge-web-apache_4.5.14-22etch4_all.deb
        Size/MD5 checksum:   704634 162e04520f993c85af6aac6565b01e90
      https://security.debian.org/pool/updates/main/g/gforge/gforge-shell-ldap_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    86126 71dce38865bdf01366a992336ae403d3
      https://security.debian.org/pool/updates/main/g/gforge/gforge-lists-mailman_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    81878 986a88180ea39ec6969f6b3f72006818
      https://security.debian.org/pool/updates/main/g/gforge/gforge-common_4.5.14-22etch4_all.deb
        Size/MD5 checksum:  1010552 cfafa0c6c1b5ba02a0d665cbe76b11cb
      https://security.debian.org/pool/updates/main/g/gforge/gforge-mta-postfix_4.5.14-22etch4_all.deb
        Size/MD5 checksum:    88306 4290daefda537d4f1f2127ee9eaabe49
    
    
      These files will probably be moved into the stable distribution on
      its next update.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb https://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    

    LinuxSecurity Poll

    Are you planning to use the 1Password password manager now that it is available to Linux users?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/35-are-you-planning-to-use-the-1password-password-manager-now-that-it-is-available-to-linux-users?task=poll.vote&format=json
    35
    radio
    [{"id":"122","title":"Yes","votes":"1","type":"x","order":"1","pct":25,"resources":[]},{"id":"123","title":"No ","votes":"2","type":"x","order":"2","pct":50,"resources":[]},{"id":"124","title":"Not sure at the moment","votes":"1","type":"x","order":"3","pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
    bottom 200

    Advisories

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.