Debian Security Advisory
DSA-3485-1 didiwiki -- security update
- Date Reported:
- 20 Feb 2016
- Affected Packages:
- didiwiki
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 815111.
In Mitre's CVE dictionary: CVE-2013-7448. - More information:
-
Alexander Izmailov discovered that didiwiki, a wiki implementation, failed to correctly validate user-supplied input, thus allowing a malicious user to access any part of the filesystem.
For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u1.
For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u1.
For the testing (stretch) and unstable (sid) distributions, this problem has been fixed in version 0.5-12.
We recommend that you upgrade your didiwiki packages.