CVE-2010-0394: Input Validation
PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0394?
CVE-2010-0394 is considered a critical vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2010-0394?
To fix CVE-2010-0394, upgrade the Trac Git plugin to version 0.0.20080710-3+lenny1 or later, or 0.0.20090320-1 or later on Debian.
Which software is affected by CVE-2010-0394?
CVE-2010-0394 affects the Trac Git plugin versions prior to 0.0.20080710 and 0.0.20090320 on Debian systems.
What type of attack can exploit CVE-2010-0394?
CVE-2010-0394 can be exploited through crafted HTTP queries that utilize shell metacharacters to execute arbitrary commands.
Is CVE-2010-0394 specific to certain operating systems?
Yes, CVE-2010-0394 is specifically noted for vulnerabilities in the Trac Git plugin when used on Debian GNU/Linux.