Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 12.04 LTS Security Notice 1604-1: MoinMoin XSS and Access Flaws

ubuntu
Calendar Grey October 11, 2012
Scroller Ubuntu
MoinMoin security flaws patched for Ubuntu platforms, encompassing XSS and authorization concerns.
Several security issues were fixed in MoinMoin.

Summary

Several security issues were fixed in MoinMoin.

Software Description:

- moin: Collaborative hypertext environment

Details:

It was discovered that MoinMoin did not properly sanitize certain input,

resulting in a cross-site scripting (XSS) vulnerability. With cross-site

scripting vulnerabilities, if a user were tricked into viewing server

output during a crafted server request, a remote attacker could exploit

this to modify the contents, or steal confidential data, within the same

domain. (CVE-2011-1058)

It was discovered that MoinMoin incorrectly handled group names that

contain virtual group names such as "All", "Known" or "Trusted". This could

result in a remote user having incorrect permissions. (CVE-2012-4404)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  python-moinmoin                 1.9.3-1ubuntu2.1

Ubuntu 11.10:
  python-moinmoin                 1.9.3-1ubuntu1.11.10.1

Ubuntu 11.04:
  python-moinmoin                 1.9.3-1ubuntu1.11.04.1

Ubuntu 10.04 LTS:
  python-moinmoin                 1.9.2-2ubuntu3.2

In general, a standard system update will make all the necessary changes.

References

CVE-2011-1058, CVE-2012-4404

Severity
important
Lowest
Low
Medium
High
Critical

October 11, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.