MoinMoin: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201210-02 / MoinMoin |
| Release Date |
October 18, 2012 |
| Latest Revision |
October 18, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-apps/moinmoin |
<
1.9.4 |
>=
1.9.4 |
All supported architectures
|
Related bugreports:
#305663, #339295
Synopsis
Multiple vulnerabilities have been found in MoinMoin, the worst of
which allowing for injection of arbitrary web script or HTML.
2.
Impact Information
Background
MoinMoin is a Python WikiEngine.
Description
Multiple vulnerabilities have been discovered in MoinMoin. Please review
the CVE identifiers referenced below for details.
Impact
These vulnerabilities in MoinMoin allow remote users to inject arbitrary
web script or HTML, to obtain sensitive information and to bypass the
textcha protection mechanism. There are several other unknown impacts and
attack vectors.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All MoinMoin users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/moinmoin-1.9.4"
|
4.
References
|