Debian Security Advisory DSA 1209-1 (trac)

Summary
The remote host is missing an update to trac announced via advisory DSA 1209-1. It was discovered that Trac, a wiki and issue tracking system for software development projects, performs insufficient validation against cross-site request forgery, which might lead to an attacker being able to perform manipulation of a Trac site with the privileges of the attacked Trac user.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.8.1-3sarge6. For the unstable distribution (sid) this problem has been fixed in version 0.10.1-1. We recommend that you upgrade your trac package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201209-1