Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Gentoo: GLSA-200411-33 High: TWiki Command Execution Risk

gentoo
Calendar Grey November 24, 2004
Dist Gentoo Esm H88
TWiki administrators are urged to perform upgrades in light of a critical vulnerability that enables unauthorized command execution. Prompt intervention is essential.
A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki.

Summary

Gentoo Linux Security Advisory GLSA 200411-33 https://security.gentoo.org/ Severity: High Title: TWiki: Arbitrary command execution Date: November 24, 2004 Bugs: #71035 ID: 200411-33

Synopsis ======= A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki.
Background ========= TWiki is a Web-based groupware tool based around the concept of wiki pages that can be edited by anybody with a Web browser.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/twiki < 20040902 >= 20040902
========== The TWiki search function, which uses a shell command executed via the Perl backtick opera...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3655063_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here