Your message dated Fri, 21 Mar 2025 02:34:55 +0000
with message-id <[email protected]>
and subject line Bug#844731: fixed in dokuwiki 2024-02-06b+dfsg-7
has caused the Debian Bug report #844731,
regarding dokuwiki: CVE-2016-7964
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
844731: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844731
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: dokuwiki
Version: 0.0.20160626.a-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/splitbrain/dokuwiki/issues/1708

Hi,

the following vulnerability was published for dokuwiki. No fix
upstream AFAICS yet.

CVE-2016-7964[0]:
| The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php
| in DokuWiki 2016-06-26a and older, when media file fetching is enabled,
| has no way to restrict access to private networks. This allows users to
| scan ports of internal networks via SSRF, such as 10.0.0.1/8,
| 172.16.0.0/12, and 192.168.0.0/16.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-7964
[1] https://github.com/splitbrain/dokuwiki/issues/1708

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: dokuwiki
Source-Version: 2024-02-06b+dfsg-7
Done: Daniel Baumann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
dokuwiki, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Baumann <[email protected]> (supplier of updated dokuwiki package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 21 Mar 2025 02:39:20 +0100
Source: dokuwiki
Architecture: source
Version: 2024-02-06b+dfsg-7
Distribution: sid
Urgency: medium
Maintainer: Daniel Baumann <[email protected]>
Changed-By: Daniel Baumann <[email protected]>
Closes: 844731 844732
Changes:
 dokuwiki (2024-02-06b+dfsg-7) sid; urgency=medium
 .
   * Moving farm files into its own directory within the debian packaging
     files.
   * Rewriting dokuwiki-delsite.
   * Rewriting manpages from xml in rst.
   * Building manpages as part of the package build.
   * Using docroot variable in example mod_rewrite section of the generated
     apache configuration.
   * Correcting year in upstream copyright.
   * Removing unneded apache2 restart mechanism.
   * Updating po files for apache2 restart removal.
   * Moving debian patches to subdirectory within patches.
   * Updating todo file.
   * Adding note about CVE-2016-7964 in README.Debian (Closes: #844731).
   * Adding note about CVE-2016-7965 in README.Debian (Closes: #844732).
Checksums-Sha1:
 2a1e21c3731dc799ff5dce5bedc7909bc0fe5fda 1411 dokuwiki_2024-02-06b+dfsg-7.dsc
 72a5585589ce0da4d8945d77f16a0c284983124f 93180 
dokuwiki_2024-02-06b+dfsg-7.debian.tar.xz
 6069c96b1b517290102344bcdeab4fada8dc954c 5913 
dokuwiki_2024-02-06b+dfsg-7_amd64.buildinfo
Checksums-Sha256:
 10b03af81c35f7248f97cb9adde0a6bb5252a89c4262bf88003cef3a8a878794 1411 
dokuwiki_2024-02-06b+dfsg-7.dsc
 f0f29df4b508087ad59008ba48278558a00662783339daeeea8f5f9f4d6ff655 93180 
dokuwiki_2024-02-06b+dfsg-7.debian.tar.xz
 e9727fad6721dc567dda11082af8abbab7f6e21727c452f5d9bbe631d4a53ef1 5913 
dokuwiki_2024-02-06b+dfsg-7_amd64.buildinfo
Files:
 9626237678cd478dffe7921f8ecad402 1411 web optional 
dokuwiki_2024-02-06b+dfsg-7.dsc
 2891bb18fcdf7647cc6728b6b8860973 93180 web optional 
dokuwiki_2024-02-06b+dfsg-7.debian.tar.xz
 dc886f9dfef6c00d3d748271a1c9b9ab 5913 web optional 
dokuwiki_2024-02-06b+dfsg-7_amd64.buildinfo


-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQmmGg4gLaoSj0ERgL7tPDoCoAiLwUCZ9zLgAAKCRD7tPDoCoAi
L2LFAP9Ju4ruseMTxiwqfKOu+Oh7OZ9m2Qp6iU8GpCD9Bp6FDwEAgLTJ3fvX/H6h
st3S1H3mtz2wH/8hQXPya9ohJbxv+gs=
=zw3L
-----END PGP SIGNATURE-----

Attachment: pgpSRU_jcF80A.pgp
Description: PGP signature


--- End Message ---

Reply via email to