CVE-2016-10026

NameCVE-2016-10026
Descriptionikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-812-1, DSA-3760-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ikiwiki (PTS)jessie, jessie (lts)3.20141016.4+deb8u1fixed
stretch (security), stretch (lts), stretch3.20170111.1fixed
buster3.20190228-1fixed
bullseye, bookworm3.20200202.3-1fixed
sid, trixie3.20200202.4-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ikiwikisourcewheezy3.20120629.2+deb7u2DLA-812-1
ikiwikisourcejessie3.20141016.4DSA-3760-1
ikiwikisource(unstable)3.20161219

Notes

http://ikiwiki.info/bugs/rcs_revert_can_bypass_authorization_if_affected_files_were_renamed/
Fix: http://source.ikiwiki.branchable.com/?p=source.git;a=commitdiff;h=9cada49ed6ad24556dbe9861ad5b0a9f526167f9
https://www.openwall.com/lists/oss-security/2016/12/20/7
When fixing this issue make sure to apply the complete correct fix to
not open ikiwiki to be vulnerable for CVE-2016-9645.

Search for package or bug name: Reporting problems