Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > February 2006 > TWiki - Version 4.0.0 Production Release

February 2006

TWiki - Version 4.0.0 Production Release

ID: 00102
Ref: 101/06
Date: 02 February 2006:16:28:08
Version: 1

Title: TWiki - Version 4.0.0 Production Release
Abstract: New feature added: Security sandbox blocks all possible routes for remote command execution on the server
Vendors affected: TWiki
Operating systems affected: TWiki
Applications affected: TWiki


Title
=====
TWiki - Version 4.0.0 Production Release


Detail
======

The following is an extract from a TWiki Announcement:

The long awaited TWiki 4.0.0 Production Release aka
DakarRelease is available for download. This is a major
release replacing TWiki version 04-Sep-2004.

Download the new release from:
http://twiki.org/cgi-bin/view/Codev/TWikiRelease04x00x00

______________________________________________________________
CHANGES AND UPGRADE:

Major new features since TWiki 04-Sep-2004 release:

* WYSIWYG editor (beta)
* Revamped PatternSkin with a modern look and lots of
customization options
* Much simpler install and configuration
* Integrated session support
* Webserver-independent login/logout
* Security sandbox blocks all possible routes for remote
command execution on the server
* New editing model with conflict resolution allows freer
collaboration, without fear of overwriting other people's
changes
* Multilingual UI: Chinese, Danish, Dutch, French, German,
Portuguese, Spanish
* E-mail confirmations for registration to prevent spamming
* Hierarchical sub-web (beta)
* And many, many more enhancements

Many, many people worked on TWiki-4.0.0. A lot of changes
have been done in the engine room to make the code
maintainable and extensible. Most of the redesign and code
refactoring work in the Dakar release was done by Crawford
Currie.

The change history with contributors is at
http://TWiki.org/cgi-bin/view/TWiki/TWikiHistory

To upgrade from the 04-Sep-2004 version follow the instructions
in http://TWiki.org/cgi-bin/view/TWiki04/TWikiUpgradeGuide


- ----------------------------------------------------------------------------------

For additional information or assistance, please contact the HELP Desk by
telephone or Not Protectively Marked information may be sent via
EMail to: uniras@niscc.gov.uk

Office Hours:
Mon - Fri: 08:30 - 17:00 Hrs
Tel: +44 (0) 870 487 0748 Ext 4511
Fax: +44 (0) 870 487 0749

Outside of Office Hours:
On Call Duty Officer:
Tel: +44 (0) 870 487 0748 and follow the prompts

- ----------------------------------------------------------------------------------
UNIRAS wishes to acknowledge the contributions of TWiki for the information
contained in this Briefing.
- ----------------------------------------------------------------------------------
This Briefing contains the information released by the original author. Some
of the information may have changed since it was released. If the vulnerability
affects you, it may be prudent to retrieve the advisory from the canonical site
to ensure that you receive the most current information concerning that problem.

Reference to any specific commercial product, process, or service by trade
name, trademark manufacturer, or otherwise, does not constitute or imply
its endorsement, recommendation, or favouring by UNIRAS or NISCC. The views
and opinions of authors expressed within this notice shall not be used for
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors
or omissions contained within this briefing notice. In particular, they shall
not be liable for any loss or damage whatsoever, arising from or in connection
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST)
and has contacts with other international Incident Response Teams (IRTs) in
order to foster cooperation and coordination in incident prevention, to prompt
rapid reaction to incidents, and to promote information sharing amongst its
members and the community at large.
- ----------------------------------------------------------------------------------


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQCVAwUBQ+IpCYpao72zK539AQHwwgP/R6oTAjAKP1ldl1RCiM1axlzBsapWdl/p
motbO45K7UtnwU+RWEgwGhuMJv8JSTjULlMd8/eZlN3Jnae9n19CubEU0awQSwmD
vK55rTDVET67AwtgwCIbC13Agm74u25ulHQZBNOS7yyJiVUiMx+wGPKs/jhsaFfI
raFZYfnCzYk=
=CBr/
-----END PGP SIGNATURE-----



  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |