Debian Security Advisory

DLA-1413-1 dokuwiki -- LTS security update

Date Reported:
05 Jul 2018
Affected Packages:
dokuwiki
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 889281.
In Mitre's CVE dictionary: CVE-2017-18123.
More information:

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.

For Debian 8 Jessie, these problems have been fixed in version 0.0.20140505.a+dfsg-4+deb8u1.

We recommend that you upgrade your dokuwiki packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS