dokuwiki: CVE-2006-2945: remote authenticated users read unauthorized files

Related Vulnerabilities: CVE-2006-2945  

Debian Bug report logs - #373689
dokuwiki: CVE-2006-2945: remote authenticated users read unauthorized files

version graph

Reported by: Alec Berryman <alec@thened.net>

Date: Thu, 15 Jun 2006 04:03:01 UTC

Severity: critical

Tags: patch, security

Merged with 370785

Found in version dokuwiki/0.0.20060309-3

Fixed in version 0.0.20060309-4

Done: Matti Pöllä <mpo@iki.fi>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Matti Pöllä <mpo@iki.fi>:
Bug#373689; Package dokuwiki. (full text, mbox, link).


Acknowledgement sent to Alec Berryman <alec@thened.net>:
New Bug report received and forwarded. Copy sent to Matti Pöllä <mpo@iki.fi>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Alec Berryman <alec@thened.net>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: dokuwiki: CVE-2006-2945: remote authenticated users read unauthorized files
Date: Wed, 14 Jun 2006 22:16:17 -0500
Package: dokuwiki
Severity: important
Tags: security patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

CVE-2006-2945: "Unspecified vulnerability the user profile change
functionality in DokuWiki, when Access Control Lists are enabled, allows
remote authenticated users to read unauthorized files via unknown attack
vectors."

More details are available on the DokuWiki bug system [1], including a
one-line fix.  I have verified that this fix is not present in
0.0.20060309-3.

Please mention the CVE in your changelog.

Thanks,

Alec

[1] http://bugs.splitbrain.org/?do=details&id=825

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFEkNEBAud/2YgchcQRAnxWAKCbbCMhR8p91kFbZhJ9awbKF2eBdwCfVCoq
723oLwRvqL6qt4tvd43lYgg=
=WGK/
-----END PGP SIGNATURE-----



Severity set to `critical' from `important' Request was from Matti Pöllä <mpo@iki.fi> to control@bugs.debian.org. (full text, mbox, link).


Merged 370785 373689. Request was from Matti Pöllä <mpo@iki.fi> to control@bugs.debian.org. (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Wed, 27 Jun 2007 01:47:30 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:11:09 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.