Bug 98599 - [PATCH] www/dokuwiki: SECURITY FIX
Summary: [PATCH] www/dokuwiki: SECURITY FIX
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Aaron Dalton
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-06 21:10 UTC by Aaron Dalton
Modified: 2006-06-09 21:00 UTC (History)
1 user (show)

See Also:


Attachments
dokuwiki-20060309_2.patch (1.20 KB, patch)
2006-06-06 21:10 UTC, Aaron Dalton
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Aaron Dalton freebsd_committer freebsd_triage 2006-06-06 21:10:24 UTC
- Bump PORTREVISION
- Update distinfo

Vendor's Announcement:
Hello again!

Just two days after the last security problem another flaw was discovered.
Luckily not as bad as the last one.

Andreas .kre Solberg discovered a security flaw which allows registered
users to view page content they usually have no access to. The problem is
in the way how a successful user profile change is handled.

This affects only installs which have Access Control Lists enabled (off by
default) and restricted the READ permission for certain pages even for
logged in users. Non-authenticated users can not exploit this bug.

The package available at http://www.splitbrain.org/go/dokuwiki was updated
again to reflect the change but fixing it manually is simple, too. Info on
how to do this is available at
http://bugs.splitbrain.org/?do=details&id=825

Andi

Port maintainer (chinsan.tw@gmail.com) is cc'd.
portmgr@ and secteam@ are cc'd.

I request that the package be immediately rebuilt and distributed.

Generated with FreeBSD Port Tools 0.77
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2006-06-06 23:45:41 UTC
Responsible Changed
From-To: freebsd-ports-bugs->aaron

Submitter has GNATS access
Comment 2 Edwin Groothuis freebsd_committer freebsd_triage 2006-06-06 23:45:50 UTC
State Changed
From-To: open->feedback

Awaiting maintainers feedback
Comment 3 Aaron Dalton freebsd_committer freebsd_triage 2006-06-09 21:00:56 UTC
State Changed
From-To: feedback->closed

Committed. Thanks!