CVE-2010-0394

Publication date 10 February 2010

Last updated 24 July 2024


Ubuntu priority

PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
trac-git 10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Fixed 0.0.20080710-3ubuntu1.1
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
trac-git