Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 605534 (CVE-2017-0356) - <www-apps/ikiwiki-3.20170111: Authentication bypass via repeated parameters
Summary: <www-apps/ikiwiki-3.20170111: Authentication bypass via repeated parameters
Status: RESOLVED FIXED
Alias: CVE-2017-0356
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-13 08:39 UTC by Agostino Sarubbo
Modified: 2017-02-02 07:37 UTC (History)
1 user (show)

See Also:
Package list:
=www-apps/ikiwiki-3.20170111
Runtime testing required: Yes
stable-bot: sanity-check-


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-01-13 08:39:57 UTC
From ${URL} :

Security issues were discovered in the passwordauth plugin's use of CGI::FormBuilder, involving API design issues similar to those that led to 
CVE-2014-1572. Impact:

* An attacker who can log in to a site with a password can log in
  as a different and potentially more privileged user.
* An attacker who can create a new account can set arbitrary fields
  in the user database for that account.

Sites that enable the CGI script (cgi_wrapper) and do not disable the simple password authentication plugin (passwordauth, enabled by default) are 
affected.

References:

http://seclists.org/oss-sec/2017/q1/67
https://ikiwiki.info/security/#cve-2017-0356


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2017-01-24 18:43:49 UTC
please stabilize 3.20170111
Comment 2 Stabilization helper bot gentoo-dev 2017-01-27 11:00:40 UTC
An automated check of this bug failed - repoman reported dependency errors (21 lines truncated): 

> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: DEPEND: x86(default/linux/x86/13.0) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', 'dev-perl/Net-OpenID-Consumer', 'dev-perl/XML-Feed']
> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: RDEPEND: x86(default/linux/x86/13.0) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', '>=dev-perl/CGI-FormBuilder-3.0202', 'dev-perl/XML-Feed', 'dev-perl/LWPx-ParanoidAgent', 'dev-perl/Net-OpenID-Consumer']
> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: DEPEND: x86(default/linux/x86/13.0/desktop) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', 'dev-perl/Net-OpenID-Consumer', 'dev-perl/XML-Feed']
Comment 3 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2017-02-01 15:05:53 UTC
version 3.20170111 released

cleaned other versions
Comment 4 Aaron Bauman (RETIRED) gentoo-dev 2017-02-01 22:41:03 UTC
alice, do you want x86 stabilized still?
Comment 5 Stabilization helper bot gentoo-dev 2017-02-01 23:00:39 UTC
An automated check of this bug failed - repoman reported dependency errors (21 lines truncated): 

> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: DEPEND: x86(default/linux/x86/13.0) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', 'dev-perl/Net-OpenID-Consumer', 'dev-perl/XML-Feed']
> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: RDEPEND: x86(default/linux/x86/13.0) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', '>=dev-perl/CGI-FormBuilder-3.0202', 'dev-perl/XML-Feed', 'dev-perl/LWPx-ParanoidAgent', 'dev-perl/Net-OpenID-Consumer']
> dependency.bad www-apps/ikiwiki/ikiwiki-3.20170111.ebuild: DEPEND: x86(default/linux/x86/13.0/desktop) ['dev-perl/Text-Markdown', 'dev-perl/YAML-LibYAML', 'dev-perl/Net-OpenID-Consumer', 'dev-perl/XML-Feed']
Comment 6 Aaron Bauman (RETIRED) gentoo-dev 2017-02-02 07:37:12 UTC
amd64 is stable and tree has been cleaned by maintainer.

@maintainer, if you want x86 stabilized please open a separate stable bug.

GLSA Vote: No