Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 97458

Summary: www-apps/phpwiki: XML-RPC vulnerability (CAN-2005-1921)
Product: Gentoo Security Reporter: Thierry Carrez (RETIRED) <koon>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: Other   
Whiteboard: ~1 [noglsa]
Package list:
Runtime testing required: ---
Attachments:
Description Flags
phpwiki.patch none

Description Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 01:52:23 UTC
phpwiki includes an affected XMLRPC PHP library and should be patched.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 02:05:52 UTC
Ccing stuart. Feel free to open this bug as soon as you think it's public enough.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-07-03 09:57:38 UTC
We might have to patch this one before upstream does...
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 11:27:21 UTC
Now officially affected after latest Gulftech thing.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:09:00 UTC
Same thing as for tikiwki.
It includes some old version of phpxmlrpc code (some intermediary version),
so the fix must be backported by some PHP-aware folk (note that maybe copying
the xmlrpc.inc and xmlrpcs.inc over is sufficient ?).
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:43:39 UTC
Created attachment 62620 [details, diff]
phpwiki.patch

Backported patch from PEAR fix
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-07-04 13:49:47 UTC
web-apps: please bump with patch... and test a little (I didn't)
Comment 7 Stuart Herbert (RETIRED) gentoo-dev 2005-07-05 11:55:22 UTC
Looking at this one now ...
Comment 8 Stuart Herbert (RETIRED) gentoo-dev 2005-07-05 15:30:46 UTC
phpwiki-1.2.4 is unaffected.  phpwiki-1.3.10-r1 is now in the tree, and includes
the patch.

There's no stabilisation needed; phpwiki-1.3.10's keywords were ~ppc ~sparc ~x86.

Best regards,
Stu
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-07-06 01:32:58 UTC
Thanks everyone,
Stable version was unaffected. No GLSA published.