Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 9 Jun 2006 19:57:54 +0000 (UTC)
From:      Aaron Dalton <aaron@FreeBSD.org>
To:        ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: ports/www/dokuwiki Makefile distinfo
Message-ID:  <200606091957.k59Jvtma012598@repoman.freebsd.org>

next in thread | raw e-mail | index | archive | help
aaron       2006-06-09 19:57:54 UTC

  FreeBSD ports repository

  Modified files:
    www/dokuwiki         Makefile distinfo 
  Log:
  - Bump PORTREVISION
  - Update distinfo
  
  Vendor's Announcement:
  Hello again!
  
  Just two days after the last security problem another flaw was discovered.
  Luckily not as bad as the last one.
  
  Andreas .kre Solberg discovered a security flaw which allows registered
  users to view page content they usually have no access to. The problem is
  in the way how a successful user profile change is handled.
  
  This affects only installs which have Access Control Lists enabled (off by
  default) and restricted the READ permission for certain pages even for
  logged in users. Non-authenticated users can not exploit this bug.
  
  The package available at http://www.splitbrain.org/go/dokuwiki was updated
  again to reflect the change but fixing it manually is simple, too. Info on
  how to do this is available at
  http://bugs.splitbrain.org/?do=details&id=825
  
  Andi
  
  I request that the package be immediately rebuilt and distributed.
  
  PR:             ports/98599
  Submitted by:   aaron
  Reviewed by:    maintainer
  Approved by:    maintainer, tobez (implicit)
  Security:       http://bugs.splitbrain.org/index.php?do=details&id=825
  
  Revision  Changes    Path
  1.22      +1 -1      ports/www/dokuwiki/Makefile
  1.12      +3 -3      ports/www/dokuwiki/distinfo



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200606091957.k59Jvtma012598>