Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-1976-1 Moderate: Dokuwiki Remote Access and CSRF

debian
Calendar Grey January 22, 2010
Debian Logo
The Fedora advisory FSA-2031 addresses multiple vulnerabilities in the software package allowing users to implement necessary updates for improved protection.
Several vulnerabilities have been discovered in dokuwiki, a standards compliant simple to use wiki

Summary


Several vulnerabilities have been discovered in dokuwiki, a standards compliant
simple to use wiki.
The Common Vulnerabilities and Exposures project identifies the
following problems:


CVE-2010-0287

It was discovered that an internal variable is not properly sanitized before
being used to list directories. This can be exploited to list contents of
arbitrary directories.


CVE-2010-0288

It was discovered that the ACL Manager plugin doesn't properly check the
administrator permissions. This allow an attacker to introduce arbitrary ACL
rules and thus gaining access to a closed Wiki.


CVE-2010-0289

It was discovered that the ACL Manager plugin doesn't have protections against
cross-site request forgeries (CSRF). This can be exploited to change the
access control rules by tricking a logged in administrator into visiting
a malicious web site.


The oldstable distribution (etch) is not affected by these problems.

For the stable distribution (lenny), these problems have been fixed in
version 0.0.20080505-4+lenny1.

F...

Read the Full Advisory

Package: dokuwiki

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here