Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20131025231704.GA29781@eldamar.local>
Date: Sat, 26 Oct 2013 01:17:04 +0200
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Cc: joeyh@...ian.org
Subject: [Notification] CVE-2013-6047: ikiwiki-hosting: XSS in site creation
 interface

Hi

This is a notification for the following assigned CVE:

CVE-2013-6047: ikiwiki-hosting: XSS in site creation.

The XSS only affects ikiwiki-hosting installations
that have a controlsite set up with the makesite plugin enabled. This
vulnerability was found by Gopal Bisht.

XSS fixed in ikiwiki-hosting 0.20131025[1].

 [1] http://packages.qa.debian.org/i/ikiwiki-hosting/news/20131025T224825Z.html

Upstream commits can be found in the upstream git repository:

git://ikiwiki-hosting.branchable.com/

in commits 83b221799e409b407c60fd246fd883d068775016 and
060f1b7728a0983cc010eacebdb94f0a440d98f1.

(attached for this notification).

Regards,
Salvatore

View attachment "0001-Fix-XSS-in-site-creation-interface.-Thanks-Gopal-Bis.patch" of type "text/x-diff" (4869 bytes)

View attachment "0002-also-need-to-escape-the-HOSTNAME.patch" of type "text/x-diff" (2901 bytes)

Download attachment "signature.asc" of type "application/pgp-signature" (837 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.