DSA-1514-1 moin -- several vulnerabilities

Related Vulnerabilities: CVE-2007-2423   CVE-2007-2637   CVE-2008-0780   CVE-2008-0781   CVE-2008-0782   CVE-2008-1098   CVE-2008-1099  

Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2423 A cross-site-scripting vulnerability has been discovered in attachment handling. CVE-2007-2637 Access control lists for calendars and includes were insufficiently enforced, which could lead to information disclosure. CVE-2008-0780 A cross-site-scripting vulnerability has been discovered in the login code. CVE-2008-0781 A cross-site-scripting vulnerability has been discovered in attachment handling. CVE-2008-0782 A directory traversal vulnerability in cookie handling could lead to local denial of service by overwriting files. CVE-2008-1098 Cross-site-scripting vulnerabilities have been discovered in the GUI editor formatter and the code to delete pages. CVE-2008-1099 The macro code validates access control lists insufficiently, which could lead to information disclosure. For the stable distribution (etch), these problems have been fixed in version 1.5.3-1.2etch1. This update also includes a bugfix with respect to the encoding of password reminder mails, which doesn't have security implications. The old stable distribution (sarge) will not be updated due to the many changes and support for Sarge ending end of this month anyway. You're advised to upgrade to the stable distribution if you run moinmoin. We recommend that you upgrade your moin package.

Debian Security Advisory

DSA-1514-1 moin -- several vulnerabilities

Date Reported:
09 Mar 2008
Affected Packages:
moin
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2007-2423, CVE-2007-2637, CVE-2008-0780, CVE-2008-0781, CVE-2008-0782, CVE-2008-1098, CVE-2008-1099.
More information:

Several remote vulnerabilities have been discovered in MoinMoin, a Python clone of WikiWiki. The Common Vulnerabilities and Exposures project identifies the following problems:

  • CVE-2007-2423

    A cross-site-scripting vulnerability has been discovered in attachment handling.

  • CVE-2007-2637

    Access control lists for calendars and includes were insufficiently enforced, which could lead to information disclosure.

  • CVE-2008-0780

    A cross-site-scripting vulnerability has been discovered in the login code.

  • CVE-2008-0781

    A cross-site-scripting vulnerability has been discovered in attachment handling.

  • CVE-2008-0782

    A directory traversal vulnerability in cookie handling could lead to local denial of service by overwriting files.

  • CVE-2008-1098

    Cross-site-scripting vulnerabilities have been discovered in the GUI editor formatter and the code to delete pages.

  • CVE-2008-1099

    The macro code validates access control lists insufficiently, which could lead to information disclosure.

For the stable distribution (etch), these problems have been fixed in version 1.5.3-1.2etch4. This update also includes a bugfix with respect to the encoding of password reminder mails, which doesn't have security implications.

The old stable distribution (sarge) will not be updated due to the many changes and support for Sarge ending end of this month anyway. You're advised to upgrade to the stable distribution if you run moinmoin.

We recommend that you upgrade your moin package.

Fixed in:

Debian GNU/Linux 4.0 (stable)

Source:
http://security.debian.org/pool/updates/main/m/moin/moin_1.5.3.orig.tar.gz
http://security.debian.org/pool/updates/main/m/moin/moin_1.5.3-1.2etch4.diff.gz
http://security.debian.org/pool/updates/main/m/moin/moin_1.5.3-1.2etch4.dsc
Architecture-independent component:
http://security.debian.org/pool/updates/main/m/moin/moinmoin-common_1.5.3-1.2etch4_all.deb
http://security.debian.org/pool/updates/main/m/moin/python-moinmoin_1.5.3-1.2etch4_all.deb

MD5 checksums of the listed files are available in the original advisory.