Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian: DSA-2014-1 Moderate: MoinMoin Remote Security Concerns

debian
Calendar Grey March 12, 2010
Debian Logo
Critical alert for moin packages in Debian has been issued due to various security vulnerabilities impacting systems. Immediate action is required.
Several vulnerabilities have been discovered in moin, a python clone of WikiWiki

Summary

Several vulnerabilities have been discovered in moin, a python clone of
WikiWiki.
The Common Vulnerabilities and Exposures project identifies the
following problems:


CVE-2010-0668

Multiple security issues in MoinMoin related to configurations that have
a non-empty superuser list, the xmlrpc action enabled, the SyncPages
action enabled, or OpenID configured.


CVE-2010-0669

MoinMoin does not properly sanitize user profiles.


CVE-2010-0717

The default configuration of cfg.packagepages_actions_excluded in MoinMoin
does not prevent unsafe package actions.


In addition, this update fixes an error when processing hierarchical ACLs,
which can be exploited to access restricted sub-pages.


For the stable distribution (lenny), these problems have been fixed in
version 1.7.1-3+lenny3.

For the unstable distribution (sid), these problems have been fixed in
version 1.9.2-1, and will migrate to the testing distribution (squeeze)
shortly.


We recommend that you upgrade your moin package.

Upgrade instructions
- ---------------...

Read the Full Advisory

Package: moin

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here