Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Gigabyte Intel Z87 Motherboard Lineup Preview and more
· Microsoft to roll out Xbox dashboard UI alterations before next-gen console
· Adobe Photoshop Express now available for Windows 8 and RT
· GNOME 3.8.2 Released
· Windows 8 is an enterprise 'non-starter' because IT sees no value in changes
· What to Expect from Unity in Ubuntu 13.10
· Analysts praise Nokia's new Lumia 925
· Best Business Laptops - May 2013 and more
· openSUSE 13.1 Milestone 1 released
· How to Install Cinnamon 1.8 on Ubuntu 13.04

Upcoming News
· Gigabyte Intel Z87 Motherboard Lineup Preview
· [ANNOUNCE] libchamplain 0.12.4
· [security-announce] SUSE-SU-2013:0810-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0811-1: important: Security update for oracle-update
· [security-announce] SUSE-SU-2013:0809-1: important: Security update for Acrobat Reader
· Rosewill RDEE-12002 USB 3.0 Hard Drive Enclosure @ techPowerUp
· ASUS M5A97 R2.0 Motherboard @ Hardware Secrets
· Samsung Galaxy S4 Smartphone Review @ HardwareHeaven.com
· [RHSA-2013:0832-01] Important: kernel security update
· [Tech ARP] Hard Disk Drive Myths Debunked! Rev. 5.1

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6285 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 623 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4474 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 690 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1076 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » February 2007 » USN-423-1: MoinMoin vulnerabilities

USN-423-1: MoinMoin vulnerabilities

Posted by Bob on: 02/20/2007 11:15 PM [ Print | 0 comment(s) ]

A new MoinMoin vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-423-1 February 20, 2007
moin, moin1.3 vulnerabilities
CVE-2007-0901, CVE-2007-0902
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 5.10:
moin 1.2.4-1ubuntu2.2
python-moinmoin 1.3.4-6ubuntu1.5.10

Ubuntu 6.06 LTS:
python-moinmoin 1.5.2-1ubuntu2.2

Ubuntu 6.10:
python-moinmoin 1.5.3-1ubuntu1.2

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

A flaw was discovered in MoinMoin's debug reporting sanitizer which=20
could lead to a cross-site scripting attack. By tricking a user into=20
viewing a crafted MoinMoin URL, an attacker could execute arbitrary=20
JavaScript as the current MoinMoin user, possibly exposing the user's=20
authentication information for the domain where MoinMoin was hosted.
Only Ubuntu Breezy was vulnerable. (CVE-2007-0901)

An information leak was discovered in MoinMoin's debug reporting, which=20
could expose information about the versions of software running on the=20
host system. MoinMoin administrators can add "show_traceback=3D0" to
their site configurations to disable debug tracebacks. (CVE-2007-0902)


Updated packages for Ubuntu 5.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/moin1.3_1.3.4-6ub=
untu1.5.10.diff.gz
Size/MD5: 45055 cf953c316085948e8dc9611835921bdc
http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/moin1.3_1.3.4-6ub=
untu1.5.10.dsc
Size/MD5: 793 72c93be58cada2d2ea43a6e8904a56ac
http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/moin1.3_1.3.4.ori=
g.tar.gz
Size/MD5: 3085225 aff667e7c60c5af2525cd1381f417608
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.2.4-1ubuntu2.=
2.diff.gz
Size/MD5: 39039 5b3de304bb89b4ae0ca9a0a2a9c4703d
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.2.4-1ubuntu2.=
2.dsc
Size/MD5: 646 49eadc7ac308498b2c53cde03ab8bc72
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.2.4.orig.tar.=
gz
Size/MD5: 1142734 4fea82b27079d1db50a38cf06317cfaa

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.2.4-1ubuntu2.=
2_all.deb
Size/MD5: 875492 439ce6791bfc4634de3c20f2aedbe025
http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/moinmoin-common_1=
=2E3.4-6ubuntu1.5.10_all.deb
Size/MD5: 726416 f91ba8e0a07d25811754b6d4c62a1696
http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/python-moinmoin_1=
=2E3.4-6ubuntu1.5.10_all.deb
Size/MD5: 50240 579771bff2ed9e979a477d7b5c47c229
http://security.ubuntu.com/ubuntu/pool/universe/m/moin1.3/python2.3-moi=
nmoin_1.3.4-6ubuntu1.5.10_all.deb
Size/MD5: 584382 ed7269eefdbb71e2d060c325492cff1d
http://security.ubuntu.com/ubuntu/pool/main/m/moin1.3/python2.4-moinmoi=
n_1.3.4-6ubuntu1.5.10_all.deb
Size/MD5: 584386 c914fa345dfdd89dc5896b04f1b02acc

Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2-1ubuntu2.=
2.diff.gz
Size/MD5: 37929 15194fb653e00c43092afcd7cf7efdcd
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2-1ubuntu2.=
2.dsc
Size/MD5: 702 050a5cfec5708d8da0a1a6cc69621696
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2.orig.tar.=
gz
Size/MD5: 3975925 689ed7aa9619aa207398b996d68b4b87

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moinmoin-common_1.5.=
2-1ubuntu2.2_all.deb
Size/MD5: 1507826 a10aea39090b803979f40169b09d9eee
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python-moinmoin_1.5.=
2-1ubuntu2.2_all.deb
Size/MD5: 69418 c0c6ccb72d6086ca701806cc7375ab82
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python2.4-moinmoin_1=
=2E5.2-1ubuntu2.2_all.deb
Size/MD5: 834508 a0b20e90fd41c46caaf09229e32585e8

Updated packages for Ubuntu 6.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1ubuntu1.=
2.diff.gz
Size/MD5: 38642 4f9dbe80cf2f2fd62f962fbed248f65a
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1ubuntu1.=
2.dsc
Size/MD5: 726 379049d45f6684d2bc38f7ea5f722afe
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3.orig.tar.=
gz
Size/MD5: 4187091 e95ec46ee8de9527a39793108de22f7d

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moinmoin-common_1.5.=
3-1ubuntu1.2_all.deb
Size/MD5: 1574742 9e686f13fbda8d19c7e10db62b7b522b
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python-moinmoin_1.5.=
3-1ubuntu1.2_all.deb
Size/MD5: 73506 8fcda2db454c1492332cb764b081d902
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python2.4-moinmoin_1=
=2E5.3-1ubuntu1.2_all.deb
Size/MD5: 908884 abae777420f930a54430c6438316a20f


--kXdP64Ggrk/fb43R
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF220jH/9LqRcGPm0RAi6UAJwISBzoFoAig/9UWEx8VVh9AsI3TwCgmowS
nt2x8vX5DXXC6oH9M/Kxi/E=
=bjZm
-----END PGP SIGNATURE-----


Bookmark and Share

« Jobs and Gates to appear side-by-side at WSJ 'D' Conference · Vir.IT eXplorer Lite 6.1.57\59 »

Linux Compatible » News » February 2007 » USN-423-1: MoinMoin vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition