Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-1514-1 Critical: MoinMoin Remote Execution Vulnerabilities

debian
Calendar Grey March 9, 2008
Debian Logo
Security Bulletin DSA-1515-2 outlines critical vulnerabilities in MoinMoin that necessitate prompt remediation.
Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki

Summary


A cross-site-scripting vulnerability has been discovered in
attachment handling.

CVE-2007-2637

Access control lists for calendars and includes were
insufficiently enforced, which could lead to information
disclosure.

CVE-2008-0780

A cross-site-scripting vulnerability has been discovered in
the login code.

CVE-2008-0781

A cross-site-scripting vulnerability has been discovered in
attachment handling.

CVE-2008-0782

A directory traversal vulnerability in cookie handling could
lead to local denial of service by overwriting files.

CVE-2008-1098

Cross-site-scripting vulnerabilities have been discovered in
the GUI editor formatter and the code to delete pages.

CVE-2008-1099

The macro code validates access control lists insufficiently,
which could lead to information disclosure.


For the stable distribution (etch), these problems have been fixed in
version 1.5.3-1.2etch1. This update also includes a bugfix wrt the
enco...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here