Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 209133
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hanno Boeck <hanno@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 209133 depends on: Show dependency tree
Bug 209133 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-06 13:24 0000
Changelog for 1.6.1 lists this:
- XSS fixes
From http://moinmo.in/MoinMoinRelease1.6

They're not more specific and there seems to be no cve yet, anyway it's a
security issue.

------- Comment #1 From Bernd Marienfeldt 2008-02-06 13:41:23 0000 -------
http://hg.moinmo.in/moin/1.6/raw-file/1.6.1/docs/CHANGES shows
" * Fix XSS issue in login action."

------- Comment #2 From Jakub Moc (RETIRED) 2008-02-06 14:01:25 0000 -------
1.6.1 in webapps overlay (using distutils as it should in the first place now)
in case someone needs it urgently. :)

http://overlays.gentoo.org/svn/proj/webapps/migration/www-apps/moinmoin/

------- Comment #3 From Pierre-Yves Rofes 2008-02-06 22:34:43 0000 -------
web-apps, please bump 1.6.1 into the tree.

------- Comment #4 From Gunnar Wrobel 2008-02-15 14:25:43 0000 -------
moinmoin-1.6.1 is in the tree.

Targets:

 amd64 ppc sparc x86

@jakub:

  Thanks for the ebuild. Nice work!

------- Comment #5 From Pierre-Yves Rofes 2008-02-15 15:11:31 0000 -------
(In reply to comment #4)
> moinmoin-1.6.1 is in the tree.
> 
> Targets:
> 
>  amd64 ppc sparc x86
> 
> @jakub:
> 
>   Thanks for the ebuild. Nice work!
> 

------- Comment #6 From Markus Meier 2008-02-16 09:22:07 0000 -------
x86 stable

------- Comment #7 From Tobias Scherbaum 2008-02-19 17:19:11 0000 -------
ppc stable

------- Comment #8 From Raúl Porcel 2008-02-24 15:15:44 0000 -------
sparc stable

------- Comment #9 From Steve Dibb 2008-02-25 15:12:09 0000 -------
amd64 stable

------- Comment #10 From Peter Volkov 2008-02-25 16:23:31 0000 -------
Fixed in release snapshot.

------- Comment #11 From Sune Kloppenborg Jeppesen 2008-02-25 20:07:58 0000 -------
This one is ready for GLSA vote. I vote NO.

------- Comment #12 From Robert Buchholz 2008-02-25 22:14:40 0000 -------
I would raise the severity level on this bug, for CVE-2008-0782:
  Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows
  remote attackers to overwrite arbitrary files via ".." sequences in the
  MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can
  be leveraged for PHP code execution via the quicklinks parameter.

Anyway, YES.

------- Comment #13 From Gunnar Wrobel 2008-02-26 07:14:54 0000 -------
Removed vulnerable version. webapps done.

------- Comment #14 From Pierre-Yves Rofes 2008-02-26 08:58:20 0000 -------
voting NO too, and closing.

------- Comment #15 From Pierre-Yves Rofes 2008-02-26 09:02:35 0000 -------
Actually I missed rbu's comment. reverting my vote to YES, and request filed.

------- Comment #16 From Sune Kloppenborg Jeppesen 2008-02-26 10:07:21 0000 -------
Raising severity to C1 ie remote code execution with non standard config. Is
that correct?

------- Comment #17 From Robert Buchholz 2008-02-26 14:20:16 0000 -------
(In reply to comment #16)
> Raising severity to C1 ie remote code execution with non standard config. Is
> that correct?

ACK

------- Comment #18 From Robert Buchholz 2008-03-08 17:14:06 0000 -------
We should research this first, but I asusme this is fixes in the most recent
update, too. Hanno, can you help here?

CVE-2008-1098 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1098):
  Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and
  earlier allow remote attackers to inject arbitrary web script or HTML via (1)
  certain input processed by formatter/text_gedit.py (aka the gui editor
  formatter); (2) a page name, which triggers an injection in PageEditor.py
  when the page is successfully deleted by a victim in a DeletePage action; or
  (3) the destination page name for a RenamePage action, which triggers an
  injection in PageEditor.py when a victim's rename attempt fails because of a
  duplicate name.  NOTE: the AttachFile XSS issue is already covered by
  CVE-2008-0781, and the login XSS issue is already covered by CVE-2008-0780.

CVE-2008-1099 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1099):
  _macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly
  enforce ACLs, which allows remote attackers to read protected pages.

------- Comment #19 From Pierre-Yves Rofes 2008-03-18 22:41:29 0000 -------
GLSA 200803-27

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug