Title : Debian Security Update Fixes GForge "cvsweb.php" Command Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-1946 CVE ID : CVE-2007-0246
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-25
Technical Description
A vulnerability has been identified in Debian, which could be exploited by remote attackers to execute arbitrary code. This issue is caused by an error in GForge. For additional information, see : VUPEN/ADV-2007-1942
Debian GNU/Linux etch - Upgrade to gforge-plugin-scmcvs version 4.5.14-5
Debian GNU/Linux sid - Upgrade to gforge-plugin-scmcvs version 4.5.14-6 References