Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-03 Thread Steve Langasek
On Sat, Dec 02, 2006 at 11:45:15PM +0100, Amaya wrote: Stefan Fritsch wrote: A vulnerability has been found in twiki. See http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for details. Just for the sake of detail, your site may be vulnerable if: 1. If you have

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-03 Thread Amaya
Steve Langasek wrote: This sounds to me like it means the package is not vulnerable by default, is that correct? Should this bug be downgraded to 'important'? Yes, and there's nothing we can do as maintainers to fix this, depending on how people set up their servers. I included info on how

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-02 Thread Stefan Fritsch
Package: twiki Severity: grave Tags: security Justification: user security hole A vulnerability has been found in twiki. See http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for details. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble?

Bug#401303: CVE-2006-6071: TWiki Authentication Bypass Vulnerability

2006-12-02 Thread Amaya
Hi there, Stefan Fritsch wrote: A vulnerability has been found in twiki. See http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2006-6071 for details. Just for the sake of detail, your site may be vulnerable if: 1. If you have ErrorDocument 401 set to point to the TWikiRegistration