Debian Security Advisory
DLA-1413-1 dokuwiki -- LTS security update
- Date Reported:
- 05 Jul 2018
- Affected Packages:
- dokuwiki
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 889281.
In Mitre's CVE dictionary: CVE-2017-18123. - More information:
-
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
For Debian 8
Jessie
, these problems have been fixed in version 0.0.20140505.a+dfsg-4+deb8u1.We recommend that you upgrade your dokuwiki packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS