Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 136723
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 136723 depends on: Show dependency tree
Bug 136723 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-06-13 16:56 0000
(confirmed on the TikiWiki changelog webpage : "This release mainly enhances
security with more protection and introduces various enhancements. It includes
the security fixes in Tiki 1.9.3.2"
http://sourceforge.net/forum/forum.php?forum_id=578094 )



----------------------------------------------------------------
[#] Security Advisory
[^] http://securitynews.ir/

[>] Advisory Title: TikiWiki Sql injection & XSS Vulnerabilities
[@] Author : bug [@] securitynews.ir
[$] Product Vendor : http://tikiwiki.org/
[.] Affected Versions : 1.9.3.2 (and maybe before)
[/] Release Date : 06/13/2006
----------------------------------------------------------------
[*] Overview :
Tikiwiki is a very powerful multilingual Wiki/CMS/Groupware, but
it has some security bugs too .
One sql injection and several cross-site scripting bugs have
been found in tikiwiki 1.9.3.2 (and tested in 1.9.3.1) .

[*] Details :
No exploitable detail is going to be released .

[*] Solution :
Vendor contacted on 06/09/2006 and they have been released a new
version (tikiwiki 1.9.4) :
http://sourceforge.net/project/showfiles.php?group_id=64258

------------------------------
http://securitynews.ir/

------- Comment #1 From Raphael Marichez 2006-06-13 16:58:00 0000 -------
Hello web-apps, please work again on tikiwiki :/

1.9.3.4 is out and corrects the SQL injection vulnerability and XSS issues.

Thanks in advance

------- Comment #2 From Renat Lumpau 2006-06-17 17:27:38 0000 -------
1.9.4 in CVS

------- Comment #3 From Raphael Marichez 2006-06-17 17:33:08 0000 -------
Thanks rl03

ppc team, please test and mark stable, thank you

------- Comment #4 From Tobias Scherbaum 2006-06-25 00:37:39 0000 -------
ppc stable

------- Comment #5 From Thierry Carrez (RETIRED) 2006-06-25 10:14:52 0000 -------
I would vote yes.

------- Comment #6 From Wolf Giesen (RETIRED) 2006-06-25 10:20:15 0000 -------
Yes. (/sigh)

------- Comment #7 From Raphael Marichez 2006-06-25 11:00:13 0000 -------
because of sql injection, (and not because of the xss issue), i vote yes.

GLSA will have to be combined with bug 134483

------- Comment #8 From Sune Kloppenborg Jeppesen 2006-06-28 23:08:51 0000 -------
GLSA 200606-29

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug