Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
BID:13990
Info
Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
| Bugtraq ID: | 13990 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2005 12:00AM |
| Updated: | Jun 20 2005 12:00AM |
| Credit: | Discovery is credited to Stefan Esser <[email protected]> with Happy Python Hackers Project. |
| Vulnerable: |
Gentoo Linux Edgewall Software Trac 0.8.3 Edgewall Software Trac 0.8.1 Edgewall Software Trac 0.7.1 |
| Not Vulnerable: |
Edgewall Software Trac 0.8.4 |
Discussion
Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
Trac is affected by an unauthorized file upload/download vulnerability.
This issue can lead to information disclosure and unauthorized remote access as an attacker can place and execute malicious PHP scripts on an affected computer.
Trac 0.8.3 and prior versions are affected by this issue.
Trac is affected by an unauthorized file upload/download vulnerability.
This issue can lead to information disclosure and unauthorized remote access as an attacker can place and execute malicious PHP scripts on an affected computer.
Trac 0.8.3 and prior versions are affected by this issue.
Exploit / POC
Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
Solution:
The vendor has released an upgrade to address this issue.
Gentoo has released an advisory (GLSA 200506-21) and an updated eBuild to address this issue. Gentoo users are advised to execute the following series of commands as a superuser to apply these updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/trac-0.8.4"
Debian has released advisory DSA 739-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Edgewall Software Trac 0.7.1
Edgewall Software Trac 0.8.1
Edgewall Software Trac 0.8.3
Solution:
The vendor has released an upgrade to address this issue.
Gentoo has released an advisory (GLSA 200506-21) and an updated eBuild to address this issue. Gentoo users are advised to execute the following series of commands as a superuser to apply these updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/trac-0.8.4"
Debian has released advisory DSA 739-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Edgewall Software Trac 0.7.1
-
Edgewall Software trac-0.8.4.tar.gz
http://ftp.edgewall.com/pub/trac/trac-0.8.4.tar.gz
Edgewall Software Trac 0.8.1
-
Debian trac_0.8.1-3sarge2_all.deb
http://security.debian.org/pool/updates/main/t/trac/trac_0.8.1-3sarge2 _all.deb
Edgewall Software Trac 0.8.3
-
Edgewall Software trac-0.8.4.tar.gz
http://ftp.edgewall.com/pub/trac/trac-0.8.4.tar.gz
References
Edgewall Software Trac Unauthorized File Upload/Download Vulnerability
References:
References:
- Trac (Edgewall Software)
- Advisory 01/2005: Fileupload/download vulnerability in Trac (Stefan Esser
)