Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 106149
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Andres Pereira (RETIRED) <anpereir@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 106149 depends on: Show dependency tree
Bug 106149 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-09-15 23:19 0000
There is a new vulnerability which affects www-apps/twiki: (remote execution of
arbitrary commands with the permissions of the user running twiki)

http://www.securityfocus.com/bid/14834
http://twiki.org/cgi-bin/view/Codev/SecurityAlertExecuteCommandsWithRev

A number of countermeasures are mentioned in the above website (patches).

I installed the twiki available in portage (~20041030) and it's vulnerable. On
the other hand it seems that there is another vulnerability according to (not
tested):

http://twiki.org/cgi-bin/view/Codev/UncoordinatedSecurityAlert23Feb2005

------- Comment #1 From Thierry Carrez (RETIRED) 2005-09-16 01:55:10 0000 -------
This is public, opening.
web-apps: please bump.
Note that the package being only in ~ it won't generate a GLSA.

------- Comment #2 From Renat Lumpau 2005-09-16 04:38:50 0000 -------
Thanks for reporting, both fixed in CVS.

------- Comment #3 From Thierry Carrez (RETIRED) 2005-09-16 09:44:18 0000 -------
No GLSA, closing.

------- Comment #4 From Thierry Carrez (RETIRED) 2005-09-16 09:45:22 0000 -------
Hm. no.
Renat: you should revbump so that people get the fix by normal upgrade.

------- Comment #5 From Renat Lumpau 2005-09-16 15:58:09 0000 -------
doh. fixed.

------- Comment #6 From Thierry Carrez (RETIRED) 2005-09-17 06:25:00 0000 -------
Really closing

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug