ikiwiki Blank Password Authentication Bypass Vulnerability
BID:29479
Info
ikiwiki Blank Password Authentication Bypass Vulnerability
| Bugtraq ID: | 29479 |
| Class: | Design Error |
| CVE: |
CVE-2008-0169 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2008 12:00AM |
| Updated: | Jun 04 2008 04:03PM |
| Credit: | Joey Hess of Debian |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 ikiwiki ikiwiki 2.31.1 ikiwiki ikiwiki 2.31 ikiwiki ikiwiki 2.47 ikiwiki ikiwiki 1.34 Debian Linux 4.0 |
| Not Vulnerable: |
ikiwiki ikiwiki 2.48 |
Discussion
ikiwiki Blank Password Authentication Bypass Vulnerability
The 'ikiwiki' program is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Versions between ikiwiki 1.34 and 2.47 are vulnerable.
The 'ikiwiki' program is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Versions between ikiwiki 1.34 and 2.47 are vulnerable.
Exploit / POC
ikiwiki Blank Password Authentication Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
ikiwiki Blank Password Authentication Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
ikiwiki ikiwiki 2.47
ikiwiki ikiwiki 1.34
ikiwiki ikiwiki 2.31
ikiwiki ikiwiki 2.31.1
Solution:
The vendor has released an update. Please see the references for more information.
ikiwiki ikiwiki 2.47
-
ikiwiki ikiwiki_2.48.tar.gz
http://ftp.de.debian.org/debian/pool/main/i/ikiwiki/ikiwiki_2.48.tar.g z
ikiwiki ikiwiki 1.34
-
ikiwiki ikiwiki_2.48.tar.gz
http://ftp.de.debian.org/debian/pool/main/i/ikiwiki/ikiwiki_2.48.tar.g z
ikiwiki ikiwiki 2.31
-
ikiwiki ikiwiki_2.48.tar.gz
http://ftp.de.debian.org/debian/pool/main/i/ikiwiki/ikiwiki_2.48.tar.g z
ikiwiki ikiwiki 2.31.1
-
ikiwiki ikiwiki_2.48.tar.gz
http://ftp.de.debian.org/debian/pool/main/i/ikiwiki/ikiwiki_2.48.tar.g z
References
ikiwiki Blank Password Authentication Bypass Vulnerability
References:
References:
- Empty password security hole (ikiwiki)
- ikiwiki Homepage (ikiwiki)
- ikiwiki openid + passwordauth empty password security hole (ikiwiki)