Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Apple Seeds First OS X 10.8.5 Beta to Developers
· Microsoft will pay up to $100K for new Windows exploit techniques
· DSA 2711-1: haproxy security update
· System Builder Marathon, Q2 2013 and more
· Microsoft delivers biggest update to date to TypeScript
· Tiff/nss-pam-ldapd Updates for Debian
· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review

Upcoming News
· Kingston HyperX Beast Black 16 GB 2133 C11 (2x8 GB) @ techPowerUp
· Canon PowerShot N Review @ TechReviewSource.com
· Gunpoint Review (PC)
· E3 2013: Wrap Up Coverage @ Legit Reviews
· Cougar Spike Micro ATX Case @ LanOC Reviews
· Logitech G400s Gaming Mouse Video Review with Dave Chaos @ HardwareHeaven.com
· Intel Core i7-4770K Haswell Processor Review @ ThinkComputers.org
· Samsung EX2F Camera Review - A Low-Light Advanced Point-And-Shoot For Any Photographer
· NZXT Phantom 630 Ultra Tower
· An MTN News Flash - MEGATech Reviews: Wicked Audio EVAC Full-Size Headphones

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2675 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3455 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93224 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 185 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6900 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » May 2007 » USN-458-1: MoinMoin vulnerabilities

USN-458-1: MoinMoin vulnerabilities

Posted by Bob on: 05/08/2007 08:10 AM [ Print | 0 comment(s) ]

A new MoinMoin vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-458-1 May 07, 2007
moin vulnerabilities
CVE-2007-2423
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
python2.4-moinmoin 1.5.2-1ubuntu2.3

Ubuntu 6.10:
python2.4-moinmoin 1.5.3-1ubuntu1.3

Ubuntu 7.04:
python-moinmoin 1.5.3-1.1ubuntu3.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

A flaw was discovered in MoinMoin's error reporting when using the=20
AttachFile action. By tricking a user into viewing a crafted MoinMoin=20
URL, an attacker could execute arbitrary JavaScript as the current=20
MoinMoin user, possibly exposing the user's authentication information=20
for the domain where MoinMoin was hosted. (CVE-2007-2423)

Flaws were discovered in MoinMoin's ACL handling for calendars and=20
includes. Unauthorized users would be able to read pages that would=20
otherwise be unavailable to them.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2-1ubuntu2.=
3.diff.gz
Size/MD5: 39487 c3b1dfe20a3bb839def08020159321ef
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2-1ubuntu2.=
3.dsc
Size/MD5: 702 584b400e32f0fae1aef2fa69ffed2bd8
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.2.orig.tar.=
gz
Size/MD5: 3975925 689ed7aa9619aa207398b996d68b4b87

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moinmoin-common_1.5.=
2-1ubuntu2.3_all.deb
Size/MD5: 1507924 c53bc6a1452309b150dc86d0884feea6
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python-moinmoin_1.5.=
2-1ubuntu2.3_all.deb
Size/MD5: 69548 cc8dd84cef4cd95749a7f3914c55b49b
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python2.4-moinmoin_1=
=2E5.2-1ubuntu2.3_all.deb
Size/MD5: 834738 950146660e787274fe0d69a8ab2bff5d

Updated packages for Ubuntu 6.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1ubuntu1.=
3.diff.gz
Size/MD5: 40234 e232754328aa47d1f2c5be8252392bf3
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1ubuntu1.=
3.dsc
Size/MD5: 726 86bb330aafbfb7c428950f8646fc084b
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3.orig.tar.=
gz
Size/MD5: 4187091 e95ec46ee8de9527a39793108de22f7d

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moinmoin-common_1.5.=
3-1ubuntu1.3_all.deb
Size/MD5: 1574744 57f533196afd6198798b24eaa105d596
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python-moinmoin_1.5.=
3-1ubuntu1.3_all.deb
Size/MD5: 73640 64019d9f0109287760bfd5b4660cdc4b
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python2.4-moinmoin_1=
=2E5.3-1ubuntu1.3_all.deb
Size/MD5: 909078 f6deadb7c99624b72b08b973c0973f8f

Updated packages for Ubuntu 7.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1.1ubuntu=
3.1.diff.gz
Size/MD5: 38905 30c1f2043f7629767530923b797026c5
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3-1.1ubuntu=
3.1.dsc
Size/MD5: 671 7209cfa3f1a21c1a45dcb2ddf16cabb9
http://security.ubuntu.com/ubuntu/pool/main/m/moin/moin_1.5.3.orig.tar.=
gz
Size/MD5: 4187091 e95ec46ee8de9527a39793108de22f7d

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/moin/moinmoin-common_1.5.=
3-1.1ubuntu3.1_all.deb
Size/MD5: 1574964 e73dd559227f0712c5d453b80a08f388
http://security.ubuntu.com/ubuntu/pool/main/m/moin/python-moinmoin_1.5.=
3-1.1ubuntu3.1_all.deb
Size/MD5: 914232 26c1e3c3344c2666c1150a77b0ffcccc


--qMKY6FR9kfgQNBz7
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGQCGXH/9LqRcGPm0RAtLOAJ9/4dsEQxFd90lFvj19+xznr/KCywCgmSwC
KaGar0Q1l6ayjpiCACLC4rU=
=QLCU
-----END PGP SIGNATURE-----


Bookmark and Share

« Raw Photo Processor 3.5.5 · Codegen M701-CA Review »

Linux Compatible » News » May 2007 » USN-458-1: MoinMoin vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition