Tags:
create new tag
view all tags

SID-01289: Func.pm saveFile has insecure dependency

Status: Answered Answered TWiki version: 5.1.0 Perl version: 5.8.8
Category: CategoryError Server OS: CentOS 5, kernel 2.6.18 Last update: 13 years ago

When trying to log into our Wiki (externally authenticated via SSO through LDAP) I get the following message for users that don't yet have a mapping in the UsersList

Insecure dependency in open while running with -T switch at /var/www/twiki/lib/TWiki/Func.pm line 2652

If a user mapping exists the error doesn't occur, but the problem is that the error comes up immediately after authentication, thus preventing the user from completing their TWiki registration to facilitate the user mapping.

-- CameronWood - 2011-10-11

Discussion and Answer

That line is open( FILE, ">$name" ) of the TWiki::Func::saveFile utility function. Can you debug to see who is calling this? Obviously the file name passed to the function needs to be sanitized and untainted.

-- PeterThoeny - 2011-10-11

Closing this question after more than 30 days of inactivity. Feel free to reopen if needed. Consider engaging one of the TWiki consultants if you need timely help. We invite you to get involved with the community, it is more likely you get community support if you support the open source project!

-- PeterThoeny - 2012-01-23

      Change status to:
ALERT! If you answer a question - or someone answered one of your questions - please remember to edit the page and set the status to answered. The status selector is below the edit box.
SupportForm
Status Answered
Title Func.pm saveFile has insecure dependency
SupportCategory CategoryError
TWiki version 5.1.0
Server OS CentOS 5, kernel 2.6.18
Web server Apache 2.2.3-43
Perl version 5.8.8
Edit | Attach | Watch | Print version | History: r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r3 - 2012-01-23 - PeterThoeny
 
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2026 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.