Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: DSA-1720 High: Moin Authentication Vulnerability

debian
Calendar Grey January 29, 2009
Debian Logo
Ubuntu Security Notice USN-1234 alerts users to vulnerabilities in the Django framework, recommending updates to mitigate risks.
It was discovered that the AttachFile action in moin, a python clone of WikiWiki, is prone to cross-site scripting attacks (CVE-2009-0260)

Summary

It was discovered that the AttachFile action in moin, a python clone of
WikiWiki, is prone to cross-site scripting attacks (CVE-2009-0260).
Another cross-site scripting vulnerability was discovered in the
antispam feature (CVE-2009-0312).


For the stable distribution (etch) these problems have been fixed in
version 1.5.3-1.2etch2.

For the testing (lenny) distribution these problems have been fixed in
version 1.7.1-3+lenny1.

For the unstable (sid) distribution these problems have been fixed in
version 1.8.1-1.1.

We recommend that you upgrade your moin packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


De...

Read the Full Advisory

Package: moin
CVE ID: CVE-2009-0260 CVE-2009-0312

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here