Trac needs security fixes

Bug #394290 reported by Raul Wegmann
288
This bug affects 3 people
Affects Status Importance Assigned to Milestone
trac (Ubuntu)
Fix Released
Low
Unassigned
Declined for Intrepid by Kees Cook
Dapper
Won't Fix
Low
Artur Rona
Hardy
Won't Fix
Low
Artur Rona
Jaunty
Fix Released
Low
Unassigned
Karmic
Fix Released
Low
Unassigned

Bug Description

Binary package hint: trac

From http://trac.edgewall.org/wiki/ChangeLog#a0.10.5 :
- Fixes a cross-site redirection vulnerability in the quickjump function reported by Russ McRee.
- Fixes a wiki engine XSS vulnerability found by Nathan Collins.

Ubuntu hardy ships version 0.10.4.

Related branches

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

visibility: private → public
Changed in trac (Ubuntu):
importance: Undecided → Low
status: New → Confirmed
Artur Rona (ari-tczew)
summary: - Trac 0.10.5 contains two security fixes
+ Trac needs security fixes
Artur Rona (ari-tczew)
Changed in trac (Ubuntu Karmic):
status: New → Confirmed
Artur Rona (ari-tczew)
Changed in trac (Ubuntu Jaunty):
assignee: nobody → Artur Rona (ari-tczew)
Changed in trac (Ubuntu Hardy):
assignee: nobody → Artur Rona (ari-tczew)
Changed in trac (Ubuntu Dapper):
assignee: nobody → Artur Rona (ari-tczew)
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

@Artur: the patch for karmic looks okay. Could you please describe the testing you've performed to make sure it works properly after patching?

I'm unsubscribing ubuntu-security-sponsors for now. Once you've described the testing you've performed, please subscribed ubuntu-security-sponsors again.

Changed in trac (Ubuntu Karmic):
assignee: nobody → Artur Rona (ari-tczew)
status: Confirmed → Incomplete
Revision history for this message
Artur Rona (ari-tczew) wrote :

Tested OK.

Changed in trac (Ubuntu Karmic):
assignee: Artur Rona (ari-tczew) → nobody
status: Incomplete → Confirmed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

ACK karmic

Changed in trac (Ubuntu Dapper):
status: New → Confirmed
importance: Undecided → Low
Changed in trac (Ubuntu Hardy):
status: New → Confirmed
importance: Undecided → Low
Changed in trac (Ubuntu Jaunty):
status: New → Confirmed
importance: Undecided → Low
Changed in trac (Ubuntu Karmic):
importance: Undecided → Low
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Uploaded Karmic to the security PPA.

Changed in trac (Ubuntu Karmic):
status: Confirmed → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package trac - 0.11.5-2ubuntu1.1

---------------
trac (0.11.5-2ubuntu1.1) karmic-security; urgency=low

  * SECURITY UPDATE: Multiple unspecified vulnerabilities in Trac
    before 0.11.6 have unknown impact and attack vectors, possibly
    related to (1) "policy checks in report results when using alternate
    formats" or (2) a "check for the 'raw' role that is missing
    in docutils < 0.6." (LP: #394290)
    - debian/patches/21_CVE-2009-4405.dpatch
    - CVE-2009-4405
 -- Artur Rona <email address hidden> Sat, 24 Apr 2010 02:53:57 +0200

Changed in trac (Ubuntu Karmic):
status: Fix Committed → Fix Released
Artur Rona (ari-tczew)
Changed in trac (Ubuntu Jaunty):
assignee: Artur Rona (ari-tczew) → nobody
status: Confirmed → New
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Artur,

I can't get the jaunty update to build. How did you get this to build on jaunty?

Revision history for this message
Artur Rona (ari-tczew) wrote :

Oh, I've supose that I've built a correct dsc file. I've reworked and retested diff which is available on bzr branch.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for the jaunty update. The packages are being built now, and will be released today or tomorrow.

Changed in trac (Ubuntu Jaunty):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package trac - 0.11.1-2.1ubuntu0.1

---------------
trac (0.11.1-2.1ubuntu0.1) jaunty-security; urgency=low

  * SECURITY UPDATE (LP: #394290)
  * debian/patches/20_CVE-2009-4405.dpatch:
    - Multiple unspecified vulnerabilities in Trac before 0.11.6 have
      unknown impact and attack vectors, possibly related to (1) "policy
      checks in report results when using alternate formats" or (2)
      a "check for the 'raw' role that is missing in docutils < 0.6."
    - CVE-2009-4405
  * debian/rules:
    - Include /usr/share/python/python.mk
    - Pass $(py_setup_install_args) to setup.py
    - Use $(py_libdir_sh) for matching distutils installation paths
    - Fixes FTBFS
 -- Artur Rona <email address hidden> Wed, 19 May 2010 17:48:56 +0200

Changed in trac (Ubuntu Jaunty):
status: Fix Committed → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. dapper has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against dapper is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in trac (Ubuntu Dapper):
status: Confirmed → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. hardy has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against hardy is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in trac (Ubuntu Hardy):
status: Confirmed → Won't Fix
Jeremy Bícha (jbicha)
Changed in trac (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.