Bug#294688: CAN-2005-0299: Directory traversal in GForge

2005-02-10 Thread Julien Cristau
On 11/02/2005-06:32, Martin Schulze wrote: > Package: gforge > Version: 3.1-26 > Severity: grave > Tags: security sarge sid patch > > The sid/sarge version seems to be vulnerable to this. Please correct it. > The correction should be in the GForge CVS, otherwise sanitising the dir > should be ea

Bug#294688: CAN-2005-0299: Directory traversal in GForge

2005-02-10 Thread Martin Schulze
Package: gforge Version: 3.1-26 Severity: grave Tags: security sarge sid patch The sid/sarge version seems to be vulnerable to this. Please correct it. The correction should be in the GForge CVS, otherwise sanitising the dir should be easy (i.e. recursively strip "../"). Candidate: CAN-2005-0299