First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 141889
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Matthias Geerdsen <vorlon@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 141889 depends on: Show dependency tree
Bug 141889 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-27 07:53 0000
4.0.4 is vulnerable, but ~arch

details and hotfix available at the URL

--

Attack Vectors:
Supply a specially crafted HTTP POST request on the TWiki configure script.

Impact:
An intruder is able to execute arbitrary shell commands with the privileges of
the web server process, such as user nobody. Properly configured TWiki sites
with authenticated configure script are not affected.

Severity Level:
Severity 1 issue: The web server can be compromised

MITRE Name for this Vulnerability:
The Common Vulnerabilities and Exposures project has assigned the name
CVE-2006-3819 to this vulnerability.

------- Comment #1 From Wolf Giesen (RETIRED) 2006-07-27 07:57:33 0000 -------
It's ~arch, though.

------- Comment #2 From Thierry Carrez (RETIRED) 2006-07-29 05:34:40 0000 -------
web-apps please bump when you can

------- Comment #3 From Renat Lumpau 2006-08-01 14:08:44 0000 -------
-r1

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-08-02 00:33:58 0000 -------
Thx Renat.

First Last Prev Next    No search results available      Search page      Enter new bug