Several security issues were fixed in MoinMoin.. =========================================================================Ubuntu Security Notice USN-4629-1 November 11, 2020 moin vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in MoinMoin. Software Description: - moin: Collaborative hypertext environment Details: Michael Chapman discovered that MoinMoin incorrectly handled certain cache actions. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-25074) Catarina Leite discovered that MoinMoin incorrectly handled certain SVG files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-15275) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: python-moinmoin 1.9.9-1ubuntu1.2 Ubuntu 16.04 LTS: python-moinmoin 1.9.8-1ubuntu1.16.04.3 In general, a standard system update will make all the necessary changes. References: CVE-2020-15275, CVE-2020-25074 Package Information: https://launchpad.net/ubuntu/+source/moin/1.9.9-1ubuntu1.2 https://launchpad.net/ubuntu/+source/moin/1.9.8-1ubuntu1.16.04.3 . Updates addressing various MoinMoin security flaws impacting Ubuntu 20.04 and 18.04 LTS installations, promoting a safer setup.. MoinMoin Vulnerability Fix, Ubuntu Security Notice, Software Update Guide. . LinuxSecurity.com Team
Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2446-1
Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4787-1
Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's link dialogue. This only affects installations which have set up fckeditor (not enabled by default). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4318-1
Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-d40c768095 2016-12-01 14:01:53.390533 -------------------------------------------------------------------------------- Name : moin Product : Fedora 24 Version : 1.9.9 Release : 1.fc24 URL : http://moinmo.in/ Summary : MoinMoin is a WikiEngine to collaborate on easily editable web pages Description : MoinMoin is an advanced, easy to use and extensible WikiEngine with a large community of users. Said in a few words, it is about collaboration on easily editable web pages. -------------------------------------------------------------------------------- Update Information: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1394684 - CVE-2016-7146 CVE-2016-7148 moin: Javascript injection via page creation https://bugzilla.redhat.com/show_bug.cgi?id=1394684 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade moin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several cross-site scripting vulnerabilities were discovered in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's attachment dialogue (CVE-2016-7146), the AttachFile view (CVE-2016-7148) and the GUI . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3715-1
Update to 1.9.8 (RHBZ #1338003). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-b3f93ead5b 2016-09-17 22:29:37.864314 -------------------------------------------------------------------------------- Name : moin Product : Fedora 24 Version : 1.9.8 Release : 1.fc24 URL : http://moinmo.in/ Summary : MoinMoin is a WikiEngine to collaborate on easily editable web pages Description : MoinMoin is an advanced, easy to use and extensible WikiEngine with a large community of users. Said in a few words, it is about collaboration on easily editable web pages. -------------------------------------------------------------------------------- Update Information: Update to 1.9.8 (RHBZ #1338003) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1338003 - RfE: Please upgrade to moin 1.9.8 https://bugzilla.redhat.com/show_bug.cgi?id=1338003 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update moin' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
MoinMoin could be made to run programs and overwrite files.. =========================================================================Ubuntu Security Notice USN-1680-1 December 30, 2012 moin vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: MoinMoin could be made to run programs and overwrite files. Software Description: - moin: Collaborative hypertext environment Details: It was discovered that MoinMoin did not properly sanitize its input when processing AnyWikiDraw and TWikiDraw actions. A remote attacker with write access could exploit this to overwrite arbitrary files and execute arbitrary code with the priviliges of the web server (user 'www-data'). It was discovered that MoinMoin also did not properly sanitize its input when processing the AttachFile action. A remote attacker could exploit this to overwrite files via directory traversal. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: python-moinmoin 1.9.3-1ubuntu3.1 Ubuntu 12.04 LTS: python-moinmoin 1.9.3-1ubuntu2.2 Ubuntu 11.10: python-moinmoin 1.9.3-1ubuntu1.11.10.2 Ubuntu 10.04 LTS: python-moinmoin 1.9.2-2ubuntu3.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1680-1 https://bugs.launchpad.net/ubuntu/+source/moin/+bug/1094599 Package Information: https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu3.1 https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu2.2 https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu1.11.10.2 https://launchpad.net/ubuntu/+source/moin/1.9.2-2ubuntu3.3 . Uncover significant vulnerabilities in MoinMoin enablingunauthorized command execution and file modification on Ubuntu platforms. Learn more.. MoinMoin, File Overwrite, Remote Code Execution, Software Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.