Oval Definition:oval:org.mitre.oval:def:7891
Revision Date:2014-06-23Version:18
Title:DSA-1514 moin -- several vulnerabilities
Description:Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki. The Common Vulnerabilities and Exposures project identifies the following problems: A cross-site-scripting vulnerability has been discovered in attachment handling. Access control lists for calendars and includes were insufficiently enforced, which could lead to information disclosure. A cross-site-scripting vulnerability has been discovered in the login code. A cross-site-scripting vulnerability has been discovered in attachment handling. A directory traversal vulnerability in cookie handling could lead to local denial of service by overwriting files. Cross-site-scripting vulnerabilities have been discovered in the GUI editor formatter and the code to delete pages. The macro code validates access control lists insufficiently, which could lead to information disclosure.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-2423
CVE-2007-2637
CVE-2008-0780
CVE-2008-0781
CVE-2008-0782
CVE-2008-1098
CVE-2008-1099
DSA-1514
Platform(s):Debian GNU/Linux 4.0
Product(s):moin
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND Packages section
  • python-moinmoin is earlier than 1.5.3-1.2etch1
  • OR moinmoin-common is earlier than 1.5.3-1.2etch1
  • BACK