GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Sep 28, 2006 9:26 pm Post subject: [ GLSA 200609-20 ] DokuWiki: Shell command injection and Den |
|
|
Gentoo Linux Security Advisory
Title: DokuWiki: Shell command injection and Denial of Service (GLSA 200609-20)
Severity: high
Exploitable: remote
Date: September 28, 2006
Updated: December 13, 2006
Bug(s): #149266
ID: 200609-20
Synopsis
DokuWiki is vulnerable to shell command injection and Denial of Service
attacks when using ImageMagick.
Background
DokuWiki is a wiki targeted at developer teams, workgroups and small
companies. It does not use a database backend.
Affected Packages
Package: www-apps/dokuwiki
Vulnerable: < 20060309e
Unaffected: >= 20060309e
Architectures: All supported architectures
Description
Input validation flaws have been discovered in the image handling of
fetch.php if ImageMagick is used, which is not the default method.
Impact
A remote attacker could exploit the flaws to execute arbitrary shell
commands with the rights of the web server daemon or cause a Denial of
Service.
Workaround
There is no known workaround at this time.
Resolution
All DokuWiki users should upgrade to the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/dokuwiki-20060309e" |
References
DokuWiki Announcement
CVE-2006-5098
CVE-2006-5099
Last edited by GLSA on Fri Feb 07, 2014 4:23 am; edited 3 times in total |
|