Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 130399 - www-apps/trac 0.9.5 is out
Summary: www-apps/trac 0.9.5 is out
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://trac.edgewall.com/
Whiteboard: B4 [noglsa] jaervosz
Keywords:
: 130433 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-04-18 12:23 UTC by Jari-Matti Mäkelä
Modified: 2006-04-22 03:12 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jari-Matti Mäkelä 2006-04-18 12:23:58 UTC
Trac 0.9.5 is out and fixes a number of bugs and security vulnerabilities. It
would be nice to have it in portage quickly.
Thanks.

see: http://projects.edgewall.com/trac/wiki/ChangeLog
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-04-18 12:36:38 UTC
Well, eh... yay for crappy release notes. I have no idea what they mean:

# Fixed wiki macro XSS vulnerability. 
http://jvn.jp/jp/JVN%2384091359/index.html

The link is bogus and that thing has been fixed in 0.9.3 AFAIK (http://secunia.com/advisories/18465/).

Someone please verify.
Comment 2 Jari-Matti Mäkelä 2006-04-18 13:48:59 UTC
(In reply to comment #1)
> Well, eh... yay for crappy release notes. I have no idea what they mean:
> 
> # Fixed wiki macro XSS vulnerability. 
> http://jvn.jp/jp/JVN%2384091359/index.html

So it seems.

> The link is bogus and that thing has been fixed in 0.9.3 AFAIK
> (http://secunia.com/advisories/18465/).
> 
> Someone please verify.

Maybe here are better notes:

http://projects.edgewall.com/trac/log/branches/0.9-stable?rev=3201&stop_rev=2918

or here

http://projects.edgewall.com/trac/query?status=closed&milestone=0.9.5
http://projects.edgewall.com/trac/changeset/3204

I don't know about the XSS vulnerability but this is just a minor bugfix release. There are other things fixed too. Renaming the 0.9.4 ebuild -> 0.9.5 should work fine.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-04-18 23:55:27 UTC
*** Bug 130433 has been marked as a duplicate of this bug. ***
Comment 4 Julien Allanos (RETIRED) gentoo-dev 2006-04-19 00:42:31 UTC
Please jakub, add CC maintainers when reassigning, especially for security bugs.

This new vulnerability has nothing to do with the one fixed in 0.9.3 (http://secunia.com/advisories/18465/). This is a new XSS vulnerability that affect trac's macros. Default macros were fixed by sanitizing user input (http://projects.edgewall.com/trac/changeset/3201).
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-04-19 08:40:12 UTC
Julien it is the job for Security to CC maintainers. I guess Jakub is more than busy enough without having to look up maintainers.
Comment 6 Julien Allanos (RETIRED) gentoo-dev 2006-04-19 13:23:19 UTC
OK then, excuse my mistake.

www-trac-0.9.5 is now in CVS. Arches please test and stable, thanks.
Comment 7 Tobias Scherbaum (RETIRED) gentoo-dev 2006-04-20 11:59:56 UTC
ppc stable
Comment 8 Mark Loeser (RETIRED) gentoo-dev 2006-04-21 18:57:12 UTC
x86 stable
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2006-04-22 02:59:02 UTC
Ready for GLSA vote
Without more details, voting no.
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-04-22 03:12:51 UTC
Voting NO and closing.