Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 97458 - www-apps/phpwiki: XML-RPC vulnerability (CAN-2005-1921)
Summary: www-apps/phpwiki: XML-RPC vulnerability (CAN-2005-1921)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~1 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-06-30 01:52 UTC by Thierry Carrez (RETIRED)
Modified: 2005-07-06 01:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
phpwiki.patch (phpwiki.patch,959 bytes, patch)
2005-07-04 13:43 UTC, Thierry Carrez (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 01:52:23 UTC
phpwiki includes an affected XMLRPC PHP library and should be patched.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 02:05:52 UTC
Ccing stuart. Feel free to open this bug as soon as you think it's public enough.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-07-03 09:57:38 UTC
We might have to patch this one before upstream does...
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 11:27:21 UTC
Now officially affected after latest Gulftech thing.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:09:00 UTC
Same thing as for tikiwki.
It includes some old version of phpxmlrpc code (some intermediary version),
so the fix must be backported by some PHP-aware folk (note that maybe copying
the xmlrpc.inc and xmlrpcs.inc over is sufficient ?).
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:43:39 UTC
Created attachment 62620 [details, diff]
phpwiki.patch

Backported patch from PEAR fix
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:49:47 UTC
web-apps: please bump with patch... and test a little (I didn't)
Comment 7 Stuart Herbert (RETIRED) gentoo-dev 2005-07-05 11:55:22 UTC
Looking at this one now ...
Comment 8 Stuart Herbert (RETIRED) gentoo-dev 2005-07-05 15:30:46 UTC
phpwiki-1.2.4 is unaffected.  phpwiki-1.3.10-r1 is now in the tree, and includes
the patch.

There's no stabilisation needed; phpwiki-1.3.10's keywords were ~ppc ~sparc ~x86.

Best regards,
Stu
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-07-06 01:32:58 UTC
Thanks everyone,
Stable version was unaffected. No GLSA published.