Several vulnerabilities have been discovered in moin, a python clone of
WikiWiki.
The Common Vulnerabilities and Exposures project identifies the
following problems:
CVE-2010-0668
Multiple security issues in MoinMoin related to configurations that have
a non-empty superuser list, the xmlrpc action enabled, the SyncPages
action enabled, or OpenID configured.
CVE-2010-0669
MoinMoin does not properly sanitize user profiles.
CVE-2010-0717
The default configuration of cfg.packagepages_actions_excluded in MoinMoin
does not prevent unsafe package actions.
In addition, this update fixes an error when processing hierarchical ACLs,
which can be exploited to access restricted sub-pages.
For the stable distribution (lenny), these problems have been fixed in
version 1.7.1-3+lenny3.
For the unstable distribution (sid), these problems have been fixed in
version 1.9.2-1, and will migrate to the testing distribution (squeeze)
shortly.
We recommend that you upgrade your moin package.
Upgrade instructions
- ---------------...
Get the latest Linux and open source security news straight to your inbox.