Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 603434 (CVE-2016-10026) - <www-apps/ikiwiki-3.20170111: authorization bypass when reverting changes (CVE-2016-10026)
Summary: <www-apps/ikiwiki-3.20170111: authorization bypass when reverting changes (CV...
Status: RESOLVED FIXED
Alias: CVE-2016-10026
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-12-22 08:34 UTC by Agostino Sarubbo
Modified: 2017-01-30 22:28 UTC (History)
1 user (show)

See Also:
Package list:
=www-apps/ikiwiki-3.20170111
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-12-22 08:34:35 UTC
From ${URL} :

Reference: http://ikiwiki.info/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed/
Vulnerable versions: < 3.20161219
Fixed versions: >= 3.20161219
Fix: http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=9cada49ed6ad24556dbe9861ad5b0a9f526167f9

ikiwiki is a static site generator with some dynamic features,
used for wikis, blogs and other websites.

intrigeri discovered that on sites with the git and recentchanges
plugins and the CGI interface enabled, the revert links on the
RecentChanges page could revert changes on a page the logged-in user
cannot legitimately edit, if the change being reverted was made before
the page was renamed from a location that the logged-in user *could*
legitimately edit.




@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-08 23:41:08 UTC
@ Maintainer(s): Please bump to >=www-apps/ikiwiki-3.20161219
Comment 2 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2017-01-24 18:42:58 UTC
bumped to www-apps/ikiwiki-3.20170111
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2017-01-30 00:45:18 UTC
@ Arches,

please test and mark stable: =www-apps/ikiwiki-3.20170111
Comment 4 Agostino Sarubbo gentoo-dev 2017-01-30 13:09:37 UTC
amd64 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 5 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2017-01-30 18:59:12 UTC
cleaned
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2017-01-30 22:28:40 UTC
GLSA Vote: No