Bug#889281: dokuwiki: CVE-2017-18123: reflected file download vulnerability

2018-06-07 Thread anarcat
Hi, I have tested an update of the jessie package and things seem to work fine after merging the patch from upstream during a smoketest of a clean jessie VM. Attached is the debdiff to complete the update. A. diff -Nru dokuwiki-0.0.20140505.a+dfsg/debian/changelog

Bug#889281: dokuwiki: CVE-2017-18123: reflected file download vulnerability

2018-02-03 Thread Salvatore Bonaccorso
Source: dokuwiki Version: 0.0.20160626.a-2 Severity: important Tags: patch security upstream Forwarded: https://github.com/splitbrain/dokuwiki/issues/2029 Control: found -1 0.0.20140505.a+dfsg-4 Hi, the following vulnerability was published for dokuwiki. CVE-2017-18123[0]: | The call parameter