Boletines de Vulnerabilidades

DSA-3275 fusionforge - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Ansgar Burchardt discovered that the Git plugin for FusionForge, aweb-based project-management and collaboration software, does notsufficiently validate user provided input as parameter to the method tocreate secondary Git repositories. A remote attacker can use this flawto execute arbitrary code as root via a specially crafted URL.

More info:

https://www.debian.org/security/2015/dsa-3275

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0850 and DSA-3275.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2015-05-31
Ministerio de Defensa
CNI
CCN
CCN-CERT