MGASA-2014-0438
Dashboard / Vulnerabilities / MGASA-2014-0438
MGASA-2014-0438
Summary: Updated dokuwiki packages fix security vulnerabilities
Details: inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call (CVE-2014-8761). The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter (CVE-2014-8762). DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind (CVE-2014-8763). DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind (CVE-2014-8764).
References: https://advisories.mageia.org/MGASA-2014-0438.html, https://bugs.mageia.org/show_bug.cgi?id=14252, https://www.dokuwiki.org/changes#release_2014-09-29_hrun, http://www.freelists.org/post/dokuwiki/Fwd-Dokuwiki-maybe-security-issue-Null-byte-poisoning-in-LDAP-authentication, http://openwall.com/lists/oss-security/2014/10/16/9
Affected packages
Package
Name: dokuwiki
Purl: pkg:rpm/mageia/dokuwiki?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
