CVE-2007-1406

Publication date 10 March 2007

Last updated 17 July 2025


Ubuntu priority

Description

Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

Status

Package Ubuntu Release Status
trac 9.10 karmic
Fixed 0.10.4-1
9.04 jaunty
Fixed 0.10.4-1
8.10 intrepid
Fixed 0.10.4-1
8.04 LTS hardy
Fixed 0.10.4-1
7.10 gutsy
Fixed 0.10.4-1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities