Debian DSA-2214-1 : ikiwiki - missing input validation

low Nessus Plugin ID 53341

Synopsis

The remote Debian host is missing a security-related update.

Description

Tango discovered that ikiwiki, a wiki compiler, is not validating if the htmlscrubber plugin is enabled or not on a page when adding alternative stylesheets to pages. This enables an attacker who is able to upload custom stylesheets to add malicious stylesheets as an alternate stylesheet, or replace the default stylesheet, and thus conduct cross-site scripting attacks.

Solution

Upgrade the ikiwiki packages.

For the oldstable distribution (lenny), this problem has been fixed in version 2.53.6.

For the stable distribution (squeeze), this problem has been fixed in version 3.20100815.7.

See Also

https://packages.debian.org/source/squeeze/ikiwiki

https://www.debian.org/security/2011/dsa-2214

Plugin Details

Severity: Low

ID: 53341

File Name: debian_DSA-2214.nasl

Version: 1.11

Type: local

Agent: unix

Published: 4/11/2011

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Low

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:ikiwiki, cpe:/o:debian:debian_linux:6.0, cpe:/o:debian:debian_linux:5.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 4/8/2011

Reference Information

CVE: CVE-2011-1401

DSA: 2214