~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
Candidate: CVE-2009-1339
PublicDate: 2009-04-30
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1339
 http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339
Description:
 Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1
 allows remote authenticated users to hijack the authentication of arbitrary
 users for requests that update pages, as demonstrated by a URL for a save
 script in the SRC attribute of an IMG element, a related issue to
 CVE-2009-1434.
Ubuntu-Description:
Notes:
Bugs:
 https://bugs.edge.launchpad.net/ubuntu/+source/twiki/+bug/383085
Priority: medium
Discovered-by:
Assigned-to:

Patches_twiki:
 upstream: http://twiki.org/p/pub/Codev/SecurityAlert-CVE-2009-1339/TWiki-4.3.0-c-diff-cve-2009-1339.txt
upstream_twiki: needs-triage
dapper_twiki: ignored (reached end-of-life)
hardy_twiki: ignored (reached end-of-life)
intrepid_twiki: needs-triage (reached end-of-life)
jaunty_twiki: ignored (reached end-of-life)
karmic_twiki: ignored (reached end-of-life)
lucid_twiki: DNE
maverick_twiki: DNE
natty_twiki: DNE
oneiric_twiki: DNE
devel_twiki: DNE