DSA-2593-1 moin -- several vulnerabilities

Related Vulnerabilities: CVE-2012-6080   CVE-2012-6081   CVE-2012-6082   CVE-2012-6495  

It was discovered that missing input validation in the twikidraw and anywikidraw actions can result in the execution of arbitrary code. This security issue is being actively exploited. This update also addresses path traversal in AttachFile. For the stable distribution (squeeze), this problem has been fixed in version 1.9.3-1+squeeze4. For the unstable distribution (sid), this problem has been fixed in version 1.9.5-4. We recommend that you upgrade your moin packages.

Debian Security Advisory

DSA-2593-1 moin -- several vulnerabilities

Date Reported:
29 Dec 2012
Affected Packages:
moin
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-6080, CVE-2012-6081, CVE-2012-6082, CVE-2012-6495.
More information:

It was discovered that missing input validation in the twikidraw and anywikidraw actions can result in the execution of arbitrary code. This security issue is being actively exploited.

This update also addresses path traversal in AttachFile.

For the stable distribution (squeeze), this problem has been fixed in version 1.9.3-1+squeeze4.

For the unstable distribution (sid), this problem has been fixed in version 1.9.5-4.

We recommend that you upgrade your moin packages.