Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
172

Ubuntu 18.04/16.04 LTS: USN-4629-1 Moderate: MoinMoin Code Execution

Several security issues were fixed in MoinMoin.. =========================================================================Ubuntu Security Notice USN-4629-1 November 11, 2020 moin vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in MoinMoin. Software Description: - moin: Collaborative hypertext environment Details: Michael Chapman discovered that MoinMoin incorrectly handled certain cache actions. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-25074) Catarina Leite discovered that MoinMoin incorrectly handled certain SVG files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2020-15275) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: python-moinmoin 1.9.9-1ubuntu1.2 Ubuntu 16.04 LTS: python-moinmoin 1.9.8-1ubuntu1.16.04.3 In general, a standard system update will make all the necessary changes. References: CVE-2020-15275, CVE-2020-25074 Package Information: https://launchpad.net/ubuntu/+source/moin/1.9.9-1ubuntu1.2 https://launchpad.net/ubuntu/+source/moin/1.9.8-1ubuntu1.16.04.3 . Updates addressing various MoinMoin security flaws impacting Ubuntu 20.04 and 18.04 LTS installations, promoting a safer setup.. MoinMoin Vulnerability Fix, Ubuntu Security Notice, Software Update Guide. . LinuxSecurity.com Team

Calendar 2 Nov 11, 2020 Ubuntu
197

Debian 9: DLA-2446-1 moderate: Moin Remote Code Execution and XSS

Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2446-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz November 10, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : moin Version : 1.9.9-1+deb9u2 CVE ID : CVE-2020-15275 CVE-2020-25074 Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 Catarina Leite discovered that moin is prone to a stored XSS vulnerability via SVG attachments. CVE-2020-25074 Michael Chapman discovered that moin is prone to a remote code execution vulnerability via the cache action. For Debian 9 stretch, these problems have been fixed in version 1.9.9-1+deb9u2. We recommend that you upgrade your moin packages. For the detailed security status of moin please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance moin to mitigate severe XSS and remote code execution risks in Debian LTS environments.. Debian LTS, Moin, Security Update, Remote Code Execution. . LinuxSecurity.com Team

Calendar 2 Nov 10, 2020 Debian LTS
87

Debian: DSA-4787-1 Moderate: Moin Remote Code Execution and XSS

Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4787-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 09, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : moin CVE ID : CVE-2020-15275 CVE-2020-25074 Two vulnerabilities were discovered in moin, a Python clone of WikiWiki. CVE-2020-15275 Catarina Leite discovered that moin is prone to a stored XSS vulnerability via SVG attachments. CVE-2020-25074 Michael Chapman discovered that moin is prone to a remote code execution vulnerability via the cache action. For the stable distribution (buster), these problems have been fixed in version 1.9.9-1+deb10u1. We recommend that you upgrade your moin packages. For the detailed security status of moin please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-4787-1 addresses crucial vulnerabilities found in moin, notably the potential for remote code execution and stored cross-site scripting (XSS) attacks.. Debian Security Advisory,moin XSS vulnerability,remote code execution,security update,Python Wiki. . LinuxSecurity.com Team

Calendar 2 Nov 09, 2020 Debian
87

Debian 9: DSA-4318-1 Moderate: Moin Cross-Site Scripting Issue

Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's link dialogue. This only affects installations which have set up fckeditor (not enabled by default). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4318-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 15, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : moin CVE ID : CVE-2017-5934 Debian Bug : 910776 Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's link dialogue. This only affects installations which have set up fckeditor (not enabled by default). For the stable distribution (stretch), this problem has been fixed in version 1.9.9-1+deb9u1. We recommend that you upgrade your moin packages. For the detailed security status of moin please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-4320-2 highlights a critical vulnerability in the phpMyAdmin application. Prompt action required for patching.. Debian Security, Moin Update, Cross-Site Scripting, Python Application. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 15, 2018 Important Debian
89

Fedora 24: FEDORA-2016-d40c768095 critical: moin JavaScript Injection

Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-d40c768095 2016-12-01 14:01:53.390533 -------------------------------------------------------------------------------- Name : moin Product : Fedora 24 Version : 1.9.9 Release : 1.fc24 URL : http://moinmo.in/ Summary : MoinMoin is a WikiEngine to collaborate on easily editable web pages Description : MoinMoin is an advanced, easy to use and extensible WikiEngine with a large community of users. Said in a few words, it is about collaboration on easily editable web pages. -------------------------------------------------------------------------------- Update Information: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1394684 - CVE-2016-7146 CVE-2016-7148 moin: Javascript injection via page creation https://bugzilla.redhat.com/show_bug.cgi?id=1394684 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade moin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Fedora 24 update tackles significant vulnerabilities related to Javascript injection, ensuring enhanced security measures.. MoinMoin Update, Fedora Security,Bugfix Release. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 01, 2016 Critical Fedora
87

Debian: DSA-3715-1 Moderate: Cross-Site Scripting In Moin

Several cross-site scripting vulnerabilities were discovered in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's attachment dialogue (CVE-2016-7146), the AttachFile view (CVE-2016-7148) and the GUI . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3715-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 15, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : moin CVE ID : CVE-2016-7146 CVE-2016-7148 CVE-2016-9119 Debian Bug : 844338 844340 844341 Several cross-site scripting vulnerabilities were discovered in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor's attachment dialogue (CVE-2016-7146), the AttachFile view (CVE-2016-7148) and the GUI editor's link dialogue (CVE-2016-9119). For the stable distribution (jessie), these problems have been fixed in version 1.9.8-1+deb8u1. We recommend that you upgrade your moin packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recently issued Debian security notice DSA-3715-1 outlines vulnerabilities related to cross-site scripting found in Moin; users are advised to upgrade.. Cross-Site Scripting, Debian Security, Moin Update, Python Threats. . LinuxSecurity.com Team

Calendar 2 Nov 15, 2016 Debian
89

Fedora 24: FEDORA-2016-b3f93ead5b Critical: Moin 1.9.8 Security Update

Update to 1.9.8 (RHBZ #1338003). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-b3f93ead5b 2016-09-17 22:29:37.864314 -------------------------------------------------------------------------------- Name : moin Product : Fedora 24 Version : 1.9.8 Release : 1.fc24 URL : http://moinmo.in/ Summary : MoinMoin is a WikiEngine to collaborate on easily editable web pages Description : MoinMoin is an advanced, easy to use and extensible WikiEngine with a large community of users. Said in a few words, it is about collaboration on easily editable web pages. -------------------------------------------------------------------------------- Update Information: Update to 1.9.8 (RHBZ #1338003) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1338003 - RfE: Please upgrade to moin 1.9.8 https://bugzilla.redhat.com/show_bug.cgi?id=1338003 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update moin' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 25 patch for moin 1.9.9 resolves known bugs alongside enhanced teamwork functionalities.. Fedora Update,Moin Security,WikiEngine Update,Collaboration Tools. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 18, 2016 Critical Fedora
172

Ubuntu 12.10 USN-1680-1 Critical: MoinMoin File Overwrite Threat

MoinMoin could be made to run programs and overwrite files.. =========================================================================Ubuntu Security Notice USN-1680-1 December 30, 2012 moin vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: MoinMoin could be made to run programs and overwrite files. Software Description: - moin: Collaborative hypertext environment Details: It was discovered that MoinMoin did not properly sanitize its input when processing AnyWikiDraw and TWikiDraw actions. A remote attacker with write access could exploit this to overwrite arbitrary files and execute arbitrary code with the priviliges of the web server (user 'www-data'). It was discovered that MoinMoin also did not properly sanitize its input when processing the AttachFile action. A remote attacker could exploit this to overwrite files via directory traversal. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: python-moinmoin 1.9.3-1ubuntu3.1 Ubuntu 12.04 LTS: python-moinmoin 1.9.3-1ubuntu2.2 Ubuntu 11.10: python-moinmoin 1.9.3-1ubuntu1.11.10.2 Ubuntu 10.04 LTS: python-moinmoin 1.9.2-2ubuntu3.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1680-1 https://bugs.launchpad.net/ubuntu/+source/moin/+bug/1094599 Package Information: https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu3.1 https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu2.2 https://launchpad.net/ubuntu/+source/moin/1.9.3-1ubuntu1.11.10.2 https://launchpad.net/ubuntu/+source/moin/1.9.2-2ubuntu3.3 . Uncover significant vulnerabilities in MoinMoin enablingunauthorized command execution and file modification on Ubuntu platforms. Learn more.. MoinMoin, File Overwrite, Remote Code Execution, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 30, 2012 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here