DSA 1715-1: New moin packages fix insufficient input sanitising
Posted on: 01/29/2009 08:20 AM

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:

Debian Security Advisory DSA-1715
http://www.debian.org/security/
January 29, 2009
Package : moin
Vulnerability : insufficient input sanitising
Problem type : remote
Debian-specific: no
CVE ID : CVE-2009-0260 CVE-2009-0312
Debian Bug : 513158

It was discovered that the AttachFile action in moin, a python clone of
WikiWiki, is prone to cross-site scripting attacks (CVE-2009-0260).
Another cross-site scripting vulnerability was discovered in the
antispam feature (CVE-2009-0312).

For the stable distribution (etch) these problems have been fixed in
version 1.5.3-1.2etch2.

For the testing (lenny) distribution these problems have been fixed in
version 1.7.1-3+lenny1.

For the unstable (sid) distribution these problems have been fixed in
version 1.8.1-1.1.

We recommend that you upgrade your moin packages.

Debian GNU/Linux 4.0 alias etch
Debian (stable)
Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

These files will probably be moved into the stable distribution on
its next update.

