Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Gentoo: GLSA-200411-33 High: TWiki Command Execution Risk

gentoo
Calendar Grey November 24, 2004
Scroller Gentoo
TWiki administrators are urged to perform upgrades in light of a critical vulnerability that enables unauthorized command execution. Prompt intervention is essential.
A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki.

Summary

Gentoo Linux Security Advisory GLSA 200411-33 https://security.gentoo.org/ Severity: High Title: TWiki: Arbitrary command execution Date: November 24, 2004 Bugs: #71035 ID: 200411-33

Synopsis ======= A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki.
Background ========= TWiki is a Web-based groupware tool based around the concept of wiki pages that can be edited by anybody with a Web browser.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/twiki < 20040902 >= 20040902
========== The TWiki search function, which uses a shell command executed via the Perl backtick opera...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround