First published: Tue Apr 10 2018(Updated: )
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ikiwiki | 3.20200202.3-1 3.20200202.4-2.1 | |
Ikiwiki Hosting Project | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-9645 is classified as moderate.
To fix CVE-2016-9645, upgrade to Ikiwiki version 3.20161229 or later.
CVE-2016-9645 was caused by an incomplete fix for CVE-2016-10026, allowing editing restriction bypass.
Ikiwiki versions prior to 3.20161229, specifically those before version 2.8, are affected by CVE-2016-9645.
Yes, Git versions older than 2.8.0 can exploit the vulnerability outlined in CVE-2016-9645.