CVE-2009-5014

Publication date 6 November 2010

Last updated 17 July 2025


Ubuntu priority

Description

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.

Status

Package Ubuntu Release Status
turbogears2 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release