Bug#328557: twiki: TWiki Remote Command Execution Vulnerability

2005-09-16 Thread Paul Szabo
Sven, > why are you running a totally outdated twiki package? Because I am an idiot, with a badly mis-configured APT! (That I inherited this machine recently is no excuse.) Thanks for putting me on the right path: now all fixed. Sorry about the wasted bandwidth. Please close this bug. Cheers,

Bug#328557: twiki: TWiki Remote Command Execution Vulnerability

2005-09-15 Thread Sven Dowideit
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 why are you running a totally outdated twiki package? http://packages.debian.org/unstable/web/twiki only lists 20040902-3, in which this problem has been solved using the robustness patch from Florian Weimer <[EMAIL PROTECTED]> Cheers Sven Paul Sza

Bug#328557: twiki: TWiki Remote Command Execution Vulnerability

2005-09-15 Thread Paul Szabo
Package: twiki Version: 20030201-6 Severity: critical Justification: root security hole Please see http://www.securityfocus.com/archive/1/410721 Verified with http://iw/iw/view/Main/TWikiUsers?rev=3D2%20%7Cless%20/etc/passwd http://iw/iw/view/Main/TWikiUsers?rev=3D2%20%7Cps%20aux|cat%20