Package: trac
Version: 0.10-3dkg1
Severity: grave
Tags: security
Justification: user security hole


Trac 0.10.1 is now available.  It contains a fix for a CSRF
vulnerability: 

  http://trac.edgewall.org/wiki/TracDownload

It would be great if this new version could make it into debian soon.

Thanks for maintaining trac in debian!

        --dkg

-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (500, 'testing'), (200, 'unstable'), (101, 'experimental')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.17-2-686
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages trac depends on:
ii  python                        2.4.3-11   An interactive high-level object-o
ii  python-clearsilver            0.10.3-4   python bindings for clearsilver
ii  python-pysqlite2              2.3.2-1    python interface to SQLite 3
ii  python-subversion             1.4.0-5    Python bindings for Subversion
ii  python-support                0.5.4      automated rebuilding support for p
ii  subversion                    1.4.0-5    Advanced version control system

Versions of packages trac recommends:
ii  apache2                       2.2.3-3    Next generation, scalable, extenda
ii  apache2-mpm-prefork [httpd]   2.2.3-3    Traditional model for Apache HTTPD
pn  python-setuptools             <none>     (no description available)

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to