CVE-2007-1406: Critical severity edgewall trac vulnerability
Published Mar 10, 2007
·Updated
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.
Affected Software
5 affected componentsFixes available
pip/trac<0.10.3.1
0.10.3.1
Edgewall Software Trac=0.10.3
Edgewall Software Trac=0.10
Edgewall Software Trac=0.10.2
Edgewall Software Trac=0.10.1
Event History
Mar 10, 2007
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·05:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2007-1406?
The severity of CVE-2007-1406 is currently unknown as it does not specify an impact level.
2
How do I fix CVE-2007-1406?
To fix CVE-2007-1406, upgrade Trac to version 0.10.3.1 or later.
3
Which versions of Trac are affected by CVE-2007-1406?
Versions of Trac prior to 0.10.3.1, including 0.10, 0.10.1, 0.10.2, and 0.10.3, are affected by CVE-2007-1406.
4
What type of attack vectors are associated with CVE-2007-1406?
CVE-2007-1406 is noted to have remote attack vectors, though specifics are not detailed.
5
Does CVE-2007-1406 require immediate attention?
Given its unknown impact and lack of severity rating, it should be assessed based on your specific use case and risk tolerance.