ports/98599: [PATCH] www/dokuwiki: SECURITY FIX

Aaron Dalton aaron at FreeBSD.org
Tue Jun 6 20:17:15 UTC 2006

>Number:         98599
>Category:       ports
>Synopsis:       [PATCH] www/dokuwiki: SECURITY FIX
>Confidential:   no
>Severity:       critical
>Priority:       high
>Responsible:    freebsd-ports-bugs
>State:          open
>Class:          update
>Submitter-Id:   current-users
>Arrival-Date:   Tue Jun 06 20:10:24 GMT 2006
>Originator:     Aaron Dalton
>Release:        FreeBSD 5.4-RELEASE i386
System: FreeBSD moondance.itsy-bitsy.net 5.4-RELEASE FreeBSD 5.4-RELEASE #0: Sun May  8 10:21:06 UTC
- Update distinfo

Vendor's Announcement:
Hello again!

Just two days after the last security problem another flaw was discovered.
Luckily not as bad as the last one.

Andreas .kre Solberg discovered a security flaw which allows registered
users to view page content they usually have no access to. The problem is
in the way how a successful user profile change is handled.

This affects only installs which have Access Control Lists enabled (off by
default) and restricted the READ permission for certain pages even for
logged in users. Non-authenticated users can not exploit this bug.

The package available at http://www.splitbrain.org/go/dokuwiki was updated
again to reflect the change but fixing it manually is simple, too. Info on
how to do this is available at


Port maintainer (chinsan.tw at gmail.com) is cc'd.
portmgr@ and secteam@ are cc'd.

I request that the package be immediately rebuilt and distributed.

Generated with FreeBSD Port Tools 0.77

--- dokuwiki-20060309_2.patch begins here ---
Index: Makefile
RCS file: /home/pcvs/ports/www/dokuwiki/Makefile,v
retrieving revision 1.21
diff -u -u -r1.21 Makefile
--- Makefile	5 Jun 2006 20:04:48 -0000	1.21
+++ Makefile	6 Jun 2006 19:49:42 -0000
@@ -7,7 +7,7 @@
 PORTNAME=	dokuwiki
 MASTER_SITES=	http://www.splitbrain.org/_media/projects/dokuwiki/ \
Index: distinfo
RCS file: /home/pcvs/ports/www/dokuwiki/distinfo,v
retrieving revision 1.11
diff -u -u -r1.11 distinfo
--- distinfo	5 Jun 2006 18:15:04 -0000	1.11
+++ distinfo	6 Jun 2006 19:49:42 -0000
@@ -1,3 +1,3 @@
-MD5 (dokuwiki-2006-03-09.tgz) = cc513a6e9a2cb04a464461a3395bb2ec
-SHA256 (dokuwiki-2006-03-09.tgz) = 350eed365cafb25a491a0482e75c53c64d3224d762152f30bc914a34ce973c8f
-SIZE (dokuwiki-2006-03-09.tgz) = 835031
+MD5 (dokuwiki-2006-03-09.tgz) = 73db29a2e92f5708d91cf1a535290000
+SHA256 (dokuwiki-2006-03-09.tgz) = 1976d90c2a32dcc2d3a6644f8a7f09d152bc3ebcb7fd09aaf0aacaca68dd7507
+SIZE (dokuwiki-2006-03-09.tgz) = 835163
--- dokuwiki-20060309_2.patch ends here ---


More information about the freebsd-ports-bugs mailing list