DSA-1553-1 ikiwiki -- cross-site request forgery

Related Vulnerabilities: CVE-2008-0165  

It has been discovered that ikiwiki, a Wiki implementation, does not guard password and content changes against cross-site request forgery (CSRF) attacks. For the stable distribution (etch), this problem has been fixed in version 1.33.5. For the unstable distribution (sid), this problem has been fixed in version 2.42. We recommend that you upgrade your ikiwiki package.

Debian Security Advisory

DSA-1553-1 ikiwiki -- cross-site request forgery

Date Reported:
20 Apr 2008
Affected Packages:
ikiwiki
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 475445.
In Mitre's CVE dictionary: CVE-2008-0165.
More information:

It has been discovered that ikiwiki, a Wiki implementation, does not guard password and content changes against cross-site request forgery (CSRF) attacks.

For the stable distribution (etch), this problem has been fixed in version 1.33.5.

For the unstable distribution (sid), this problem has been fixed in version 2.42.

We recommend that you upgrade your ikiwiki package.

Fixed in:

Debian GNU/Linux 4.0 (etch)

Source:
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_1.33.5.tar.gz
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_1.33.5.dsc
Architecture-independent component:
http://security.debian.org/pool/updates/main/i/ikiwiki/ikiwiki_1.33.5_all.deb

MD5 checksums of the listed files are available in the original advisory.