Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-03 Thread Amaya
Steve Langasek wrote: > This sounds to me like it means the package is not vulnerable by > default, is that correct? Should this bug be downgraded to > 'important'? Yes, and there's nothing we can do as maintainers to fix this, depending on how people set up their servers. I included info on how

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-03 Thread Steve Langasek
On Sat, Dec 02, 2006 at 11:45:15PM +0100, Amaya wrote: > Stefan Fritsch wrote: > > A vulnerability has been found in twiki. See > > http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for > > details. > Just for the sake of detail, your site may be vulnerable if: >1. If you have E

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-02 Thread Amaya
Hi there, Stefan Fritsch wrote: > A vulnerability has been found in twiki. See > http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for > details. Just for the sake of detail, your site may be vulnerable if: 1. If you have ErrorDocument 401 set to point to the TWikiRegistratio

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-02 Thread Stefan Fritsch
Package: twiki Severity: grave Tags: security Justification: user security hole A vulnerability has been found in twiki. See http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for details. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Co