CVE-2016-10026

NameCVE-2016-10026
Descriptionikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-812-1, DSA-3760-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ikiwiki (PTS)wheezy3.20120629.2vulnerable
wheezy (security)3.20120629.2+deb7u2fixed
jessie3.20141016.3vulnerable
jessie (security)3.20141016.4fixed
stretch, sid3.20170111fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ikiwikisource(unstable)3.20161219
ikiwikisourcejessie3.20141016.4DSA-3760-1
ikiwikisourcewheezy3.20120629.2+deb7u2DLA-812-1

Notes

http://ikiwiki.info/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed/
Fix: http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=9cada49ed6ad24556dbe9861ad5b0a9f526167f9
http://www.openwall.com/lists/oss-security/2016/12/20/7
When fixing this issue make sure to apply the complete correct fix to
not open ikiwiki to be vulnerable for CVE-2016-9645.

Search for package or bug name: Reporting problems