Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 10: FEDORA-2009-9260 Important: Ikiwiki Remote Code Execution

fedora
Calendar Grey September 11, 2009
Dist Fedora Esm H88
Upgrade your ikiwiki installation on Fedora 10 to fix CVE-2009-2944, enhancing security by following the update procedure and confirming the patch is active
Fix CVE-2009-2944, see bz 520543.

Summary

Ikiwiki is a wiki compiler. It converts wiki pages into HTML pages

suitable for publishing on a website. Ikiwiki stores pages and history

in a revision control system such as Subversion or Git. There are many

other features, including support for blogging, as well as a large

array of plugins.

Update Information:

Fix CVE-2009-2944, see bz 520543.

Change Log

* Wed Sep 2 2009 Thomas Moschny - 2.72-2 - Add patch for teximg plugin: Make TeX handle preventing unsafe things; remove insufficient blacklist (fixes CVE-2009-2944, see bz 520543). * Fri Jan 2 2009 Thomas Moschny - 2.72-1 - Update to 2.72. - Patch for mtn plugin has been applied upstream. - Encoding of ikiwiki.vim has been changed to utf-8 upstream. - Use new W3M_CGI_BIN option in %install. * Tue Dec 16 2008 Thomas Moschny - 2.70-3 - Patch for monotone plugin: Prevent broken pipe message. - Cosmetic changes to satisfy rpmlint. * Mon Dec 1 2008 Ignacio Vazquez-Abrams - 2.70-2 - Rebuild for Python 2.6 * Thu Nov 20 2008 Thomas Moschny - 2.70-1 - Update to 2.70. - Install and enable the external rst plugin. - Stop filtering perl(RPC::XML*) requires. * Fri Oct 10 2008 Thomas Moschny - 2.66-1 - Update to 2.66.

References


[ 1 ] Bug #520543 - CVE-2009-2944 ikiwiki: arbitrary file read via crafted TeX commands https://bugzilla.redhat.com/show_bug.cgi?id=520543

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ikiwiki' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: ikiwiki
Product: Fedora 10
Version: 2.72
Release: 2.fc10
Summary: A wiki compiler

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here