Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 16.04 LTS: 3137-1 Moderate: MoinMoin Cross-Site Scripting

ubuntu
Calendar Grey November 23, 2016
Scroller Ubuntu
A range of vulnerabilities addressed in MoinMoin impact various Ubuntu versions, presenting potential threats of information compromise and malicious exploitation.
Several security issues were fixed in MoinMoin.

Summary

Several security issues were fixed in MoinMoin.

Software Description:

- moin: Collaborative hypertext environment

Details:

It was discovered that MoinMoin did not properly sanitize certain inputs,

resulting in cross-site scripting (XSS) vulnerabilities. With cross-site

scripting vulnerabilities, if a user were tricked into viewing server

output during a crafted server request, a remote attacker could exploit

this to modify the contents, or steal confidential data, within the same

domain.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  python-moinmoin                 1.9.8-1ubuntu1.16.10.1

Ubuntu 16.04 LTS:
  python-moinmoin                 1.9.8-1ubuntu1.16.04.1

Ubuntu 14.04 LTS:
  python-moinmoin                 1.9.7-1ubuntu2.1

Ubuntu 12.04 LTS:
  python-moinmoin                 1.9.3-1ubuntu2.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3137-1

CVE-2016-7146, CVE-2016-7148, CVE-2016-9119

November 23, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.