Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 243854 - www-apps/tikiwiki < 2.2 Multiple vulnerabilities (CVE-2008-{5318,5319})
Summary: www-apps/tikiwiki < 2.2 Multiple vulnerabilities (CVE-2008-{5318,5319})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://secunia.com/advisories/32341/
Whiteboard: B3? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-24 17:12 UTC by Robert Buchholz (RETIRED)
Modified: 2008-12-18 12:04 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-10-24 17:12:50 UTC
Secunia wrote:
Two vulnerabilities with unknown impact have been reported in
TikiWiki CMS/Groupware.

The vulnerabilities are caused due to unknown errors. No further
information is currently available.

The vulnerabilities are reported in all 2.x versions prior to 2.2.

SOLUTION:
Update to version 2.2.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor, who credits Emanuele Gentili for one of the
issues.

ORIGINAL ADVISORY:
http://info.tikiwiki.org/tiki-read_article.php?articleId=41
Comment 1 Gunnar Wrobel (RETIRED) gentoo-dev 2008-10-30 15:31:42 UTC
Added tikiwiki-2.2.

Targets:

  ppc
Comment 2 Tobias Scherbaum (RETIRED) gentoo-dev 2008-10-30 19:18:24 UTC
ppc stable
Comment 3 Gunnar Wrobel (RETIRED) gentoo-dev 2008-10-31 06:11:43 UTC
Removed vulnerable tikiwiki-2.0. webapps done.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-11-02 17:31:01 UTC
Voting no due to NO informations available
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-11-26 18:49:34 UTC
NO as wel, closing.
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-12-18 12:04:35 UTC
CVE-2008-5318 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5318):
  Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact
  and attack vectors related to "size of user-provided input," a
  different issue than CVE-2008-3653.

CVE-2008-5319 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5319):
  Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact
  and attack vectors related to tiki-error.php, a different issue than
  CVE-2008-3653.