Title : Debian Security Update Fixes Gforge Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2008-0115 CVE ID : CVE-2008-0173
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-14
Technical Description
A vulnerability has been identified in Debian, which could be exploited by attackers to execute arbitrary SQL queries. This issue is caused by an input validation error in Gforge when processing CGI parameters via certain scripts related to RSS exports, which could be exploited by malicious people to conduct SQL injection attacks.
Debian GNU/Linux sarge - Upgrade to gforge version 3.1-31sarge5
Debian GNU/Linux etch - Upgrade to gforge version 4.5.14-22etch4
Debian GNU/Linux sid - Upgrade to gforge version 4.6.99+svn6330-1 References