Bug 141889 - www-apps/twiki: arbitrary shell command execution (CVE-2006-3819)
Bug#: 141889 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: trivial Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: vorlon@gentoo.org
Component: Vulnerabilities
URL:  http://twiki.org/cgi-bin/view/Codev/SecurityAlertCmdExecWithConfigure
Summary: www-apps/twiki: arbitrary shell command execution (CVE-2006-3819)
Keywords:  
Status Whiteboard: ~1 [noglsa]
Opened: 2006-07-27 07:53 0000
Description:   Opened: 2006-07-27 07:53 0000
4.0.4 is vulnerable, but ~arch

details and hotfix available at the URL

--

Attack Vectors:
Supply a specially crafted HTTP POST request on the TWiki configure script.

Impact:
An intruder is able to execute arbitrary shell commands with the privileges of
the web server process, such as user nobody. Properly configured TWiki sites
with authenticated configure script are not affected.

Severity Level:
Severity 1 issue: The web server can be compromised

MITRE Name for this Vulnerability:
The Common Vulnerabilities and Exposures project has assigned the name
CVE-2006-3819 to this vulnerability.

------- Comment #1 From Wolf Giesen (RETIRED) 2006-07-27 07:57:33 0000 -------
It's ~arch, though.

------- Comment #2 From Thierry Carrez (RETIRED) 2006-07-29 05:34:40 0000 -------
web-apps please bump when you can

------- Comment #3 From Renat Lumpau 2006-08-01 14:08:44 0000 -------
-r1

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-08-02 00:33:58 0000 -------
Thx Renat.