DEBIAN-CVE-2016-7964

Source
https://security-tracker.debian.org/tracker/CVE-2016-7964
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-7964.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2016-7964
Upstream
Published
2016-10-31T10:59:00Z
Modified
2025-09-30T05:10:12.911122Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

References

Affected packages

Debian:11 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.20180422.a-2.1
0.0.20200729-0.1~bpo11+1
0.0.20200729-0.1
0.0.20220317~gitaeff85c-0.1~exp1
0.0.20220731.a-1
0.0.20220731.a-2
0.0.20220731.a-3

Other

2024-02-06b-0exp1
2024-02-06b-0exp2
2024-02-06b-0exp3
2024-02-06b-0exp4
2024-02-06b+dfsg-0exp1
2024-02-06b+dfsg-0exp2
2024-02-06b+dfsg-1
2024-02-06b+dfsg-2
2024-02-06b+dfsg-3
2024-02-06b+dfsg-4
2024-02-06b+dfsg-5
2024-02-06b+dfsg-6
2024-02-06b+dfsg-7
2024-02-06b+dfsg-8
2024-02-06b+dfsg-9
2025-05-14+dfsg-1

2025-05-14.*

2025-05-14.a+dfsg-1
2025-05-14.a+dfsg-2
2025-05-14.a+dfsg-3
2025-05-14.a+dfsg-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.20220731.a-2
0.0.20220731.a-3

Other

2024-02-06b-0exp1
2024-02-06b-0exp2
2024-02-06b-0exp3
2024-02-06b-0exp4
2024-02-06b+dfsg-0exp1
2024-02-06b+dfsg-0exp2
2024-02-06b+dfsg-1
2024-02-06b+dfsg-2
2024-02-06b+dfsg-3
2024-02-06b+dfsg-4
2024-02-06b+dfsg-5
2024-02-06b+dfsg-6
2024-02-06b+dfsg-7
2024-02-06b+dfsg-8
2024-02-06b+dfsg-9
2025-05-14+dfsg-1

2025-05-14.*

2025-05-14.a+dfsg-1
2025-05-14.a+dfsg-2
2025-05-14.a+dfsg-3
2025-05-14.a+dfsg-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2024-02-06b+dfsg-7

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:14 / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/debian/dokuwiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2024-02-06b+dfsg-7

Ecosystem specific

{
    "urgency": "unimportant"
}