Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-5108 | third party advisory |
https://access.redhat.com/security/cve/cve-2010-5108 | third party advisory broken link |
http://www.openwall.com/lists/oss-security/2013/02/13/2 | third party advisory mailing list |