Bug#310815: gforge: [CAN-2005-0299] path traversal vulnerability

2005-05-26 Thread Joey Hess
Martin Pitt wrote: > The changelog shows no trace that this is fixed: > > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0299 > http://www.securityfocus.com/bid/12318 > > However, I did not actually check the code; if gforge is vulnerable, > please coordinate with the security team.

Bug#310815: gforge: [CAN-2005-0299] path traversal vulnerability

2005-05-26 Thread Martin Pitt
Package: gforge Version: 3.1-31 Severity: grave Tags: security Justification: user security hole Hi! The changelog shows no trace that this is fixed: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0299 http://www.securityfocus.com/bid/12318 However, I did not actually check the code