Vulnerability Bulletins

DSA-3275 fusionforge - security update

   
Affected software Debian
 
Ansgar Burchardt discovered that the Git plugin for FusionForge, aweb-based project-management and collaboration software, does notsufficiently validate user provided input as parameter to the method tocreate secondary Git repositories. A remote attacker can use this flawto execute arbitrary code as root via a specially crafted URL.

More info:

https://www.debian.org/security/2015/dsa-3275