Bug#499534: twiki: Remote code execution vulerability.

2008-11-14 Thread Ardo van Rangelrooij
I'll upload it later today. Thanks, Ardo Sven Dowideit wrote: > I have uploaded an updated 4.1.2-5 with this and a few other things fixed. > > I've emailed Ardo asking for sponsorship, but if he's not around, would > appreciate assistance :) > > Sven -- Ardo van Rangelrooij

Bug#499534: twiki: Remote code execution vulerability.

2008-11-11 Thread Sven Dowideit
I have uploaded an updated 4.1.2-5 with this and a few other things fixed. I've emailed Ardo asking for sponsorship, but if he's not around, would appreciate assistance :) Sven -- Consulting wiki Engineer Sven Dowideit - http://fosiki.com A WikiRing Partner - http://wikiring.com Public key - htt

Bug#499534: twiki: Remote code execution vulerability.

2008-11-11 Thread Sven Dowideit
oh crepe. I thought we'd dealt with this already, but i was wrong. looking into it - 4.1.2-5 here we come. Sven -- Consulting wiki Engineer Sven Dowideit - http://fosiki.com A WikiRing Partner - http://wikiring.com Public key - http://pgp.mit.edu:11371/pks/lookup?search=Sven+Dowideit&op=index&e

Bug#499534: twiki: Remote code execution vulerability.

2008-11-06 Thread Moritz Muehlenhoff
On Tue, Oct 07, 2008 at 02:38:31PM +0200, Nico Golde wrote: > Hi Sven, > * Olivier Berger <[EMAIL PROTECTED]> [2008-09-20 12:30]: > > On Sat, Sep 20, 2008 at 08:40:02AM +1000, Sven Dowideit wrote: > > > This is _not_ a grave severity issue in the debian package, specifically > > > because configure

Bug#499534: twiki: Remote code execution vulerability.

2008-10-07 Thread Nico Golde
Hi Sven, * Olivier Berger <[EMAIL PROTECTED]> [2008-09-20 12:30]: > On Sat, Sep 20, 2008 at 08:40:02AM +1000, Sven Dowideit wrote: > > This is _not_ a grave severity issue in the debian package, specifically > > because configure (as mentioned in the advisory) is locked down using > > apache to > >

Bug#499534: twiki: Remote code execution vulerability.

2008-09-20 Thread Olivier Berger
On Sat, Sep 20, 2008 at 08:40:02AM +1000, Sven Dowideit wrote: > This is _not_ a grave severity issue in the debian package, specifically > because configure (as mentioned in the advisory) is locked down using > apache to >1 localhost >2 an admin user that is created by the installer. > .

Bug#499534: twiki: Remote code execution vulerability.

2008-09-19 Thread Sven Dowideit
This is _not_ a grave severity issue in the debian package, specifically because configure (as mentioned in the advisory) is locked down using apache to 1 localhost 2 an admin user that is created by the installer. Sven Brad Krane wrote: > Package: twiki > Version: 1:4.0.5-9.1 > Severity: g

Bug#499534: twiki: Remote code execution vulerability.

2008-09-19 Thread Nico Golde
severity 499534 important thanks Hi Brad, * Brad Krane <[EMAIL PROTECTED]> [2008-09-19 19:18]: > TWiki command execution vulnerability found in current version. US-CERT > Vulnerability Note: > http://www.kb.cert.org/vuls/id/362012 and TWiki Security Alert: > http://twiki.org/cgi-bin/view/Codev/

Bug#499534: twiki: Remote code execution vulerability.

2008-09-19 Thread Brad Krane
Package: twiki Version: 1:4.0.5-9.1 Severity: grave Tags: security Justification: user security hole TWiki command execution vulnerability found in current version. US-CERT Vulnerability Note: http://www.kb.cert.org/vuls/id/362012 and TWiki Security Alert: http://twiki.org/cgi-bin/view/Codev/S