TWiki 4.1.x CSRF vulnerability (CVE-2009-1339)

Bug #383085 reported by Fumihito YOSHIDA
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
twiki (Debian)
Fix Released
Unknown
twiki (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

TWiki 4.1.x has CSRF vulnerability, it identified with CVE-2009-1339.

http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339
> Impact
>
> An image tag can be crafted that, when viewed, updates pages with
> the attackers content in TWiki as the viewing user, including members
> of the TWikiAdminGroup. This can be used to gain administrator
> privileges, change access permissions and do other things.

It affected to Hardy,Intrepid,Jaunty,Karmic, and also affected Debian
sid/squeeze/lenny/etch too.

But, in now, we have not any actual patchs.

[References]

Original Advisory:
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339

Discussion of fix for 4.1.x about this vuln.
http://twiki.org/cgi-bin/view/Support/SID-00289

CVE References

Fumihito YOSHIDA (hito)
visibility: private → public
Revision history for this message
Fumihito YOSHIDA (hito) wrote :

FYI:
Patch aproach for hotfix are avaialble, but any actual patch is not written.
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339#Minimal_Hotfix_for_TWiki_Product

Aproachs are:
  1) changing twiki-apache conf (/etc/twiki/apache.conf), it prevent from GET access
     for sensitive previledged pages.
  2) changing templates files. it minimal included:
    * twiki/templates/messages.tmpl
    * twiki/templates/oopsmore.tmpl
    * twiki/templates/registerconfirm.tmpl

Changed in twiki (Debian):
status: Unknown → New
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and taking the time to report a bug. This package is in universe and is community supported. If you are able, perhaps you could prepare debdiffs to fix this by following https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures.

Changed in twiki (Ubuntu):
status: New → Confirmed
Changed in twiki (Debian):
status: New → Fix Released
Revision history for this message
dino99 (9d9) wrote :

Latest release having it into the archives was hardy; so closing that report.

Changed in twiki (Ubuntu):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.