This bug was fixed in the package twiki - 1:4.1.2-5ubuntu1 --------------- twiki (1:4.1.2-5ubuntu1) jaunty; urgency=low
* Merge from debian unstable, remaining changes: (LP: #301535) - Add a horrible hack to try and detect if htpasswd supports -b. - Prefer apache2 to apache in the webserver list, and add mini-httpd. - Only attempt to restart any of the apache's if /usr/sbin/apachectl exists and is executable, doing the same favour for apache2. twiki (1:4.1.2-5) unstable; urgency=emergency * fix TemplateLogin passthrough sysopen (Closes: #468159) * Arbitrary Code Execution in Configure Script (CVE-2008-3195) - Closes: #499534 * allow '-' for user & groupnames (Closes: #464174) * update Swedish strings for twiki debconf (Closes: #492648) * patch comments.tmpl to fix Comment plugin definitions (Closes: #502958) * remove optional mod-perl dependencies as it does not work yet - Closes: #482321 * remove "uninitialized value" errors in TWiki.pm (Closes: #472274) -- Bhavani Shankar <[EMAIL PROTECTED]> Mon, 24 Nov 2008 12:40:07 +0530 ** Changed in: twiki (Ubuntu) Status: Confirmed => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2008-3195 -- Please Merge twiki(4.1.2-5) from Debian unstable https://bugs.launchpad.net/bugs/301535 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs