Lucene search

K
osvGoogleOSV:DLA-79-1
HistoryOct 29, 2014 - 12:00 a.m.

dokuwiki - security update

2014-10-2900:00:00
Google
osv.dev
14

EPSS

0.006

Percentile

78.9%

This fixes a possibility of bypassing the wiki authentication when an Active
Directory is used for LDAP authentication. These two CVE are almost the same,
one apparently being a superset of the other. They are fixed together.

  • CVE-2014-8763
    DokuWiki before 2014-05-05b, when using Active Directory for LDAP
    authentication, allows remote attackers to bypass authentication via a
    password starting with a null (\0) character and a valid user name, which
    triggers an unauthenticated bind.
  • CVE-2014-8764
    DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP
    authentication, allows remote attackers to bypass authentication via a
    user name and password starting with a null (\0) character, which triggers
    an anonymous bind.

For Debian 6 Squeeze, these issues have been fixed in dokuwiki version 0.0.20091225c-10+squeeze3