Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 166022 - www-apps/moinmoin < 1.5.7 XSS CVE-2007-0857
Summary: www-apps/moinmoin < 1.5.7 XSS CVE-2007-0857
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: B4 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2007-02-09 01:09 UTC by Executioner
Modified: 2007-02-12 22:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Executioner 2007-02-09 01:09:31 UTC
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.

Reproducible: Didn't try




http://secunia.com/advisories/24096
http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES
Comment 1 Renat Lumpau (RETIRED) gentoo-dev 2007-02-09 03:41:37 UTC
1.5.7 already in the tree, needs stabling
Comment 2 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-10 22:18:53 UTC
Yes right, arches please test and mark stable moinmoin-1.5.7, thanks
Comment 3 Markus Meier gentoo-dev 2007-02-11 10:22:48 UTC
www-apps/moinmoin-1.5.7  USE="rss -vhosts"
1. emerges on x86
2. passes collision test
3. works

Portage 2.1.2-r9 (default-linux/x86/2006.1/desktop, gcc-4.1.1, glibc-2.5-r0, 2.6.18.6 i686)
=================================================================
System uname: 2.6.18.6 i686 AMD Athlon(TM) XP1800+
Gentoo Base System version 1.12.6
Timestamp of tree: Sun, 11 Feb 2007 09:00:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31
dev-lang/python:     2.3.5-r3, 2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=i686 -fomit-frame-pointer -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/X11/xkb /usr/share/config"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo /etc/texmf/web2c"
CXXFLAGS="-O2 -march=i686 -fomit-frame-pointer -pipe"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS="--nospinner"
FEATURES="autoconfig ccache collision-protect distlocks fixpackages metadata-transfer parallel-fetch sandbox sfperms strict stricter test userfetch userpriv usersandbox"
GENTOO_MIRRORS="http://mirror.switch.ch/mirror/gentoo/ http://gentoo.inode.at/"
LANG="en_GB.utf8"
LINGUAS="en de en_GB"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage/normal"
SYNC="rsync://192.168.2.1/gentoo-portage"
USE="3dnow 3dnowext X a52 aac alsa apache2 berkdb bitmap-fonts bzip2 cairo cdr cli cracklib crypt cups dbus divx4linux dlloader dri dts dvd dvdr dvdread eds emboss exif fam ffmpeg firefox fortran gdbm gif gnome gphoto2 gpm gstreamer gtk hal iconv ipv6 isdnlog java jpeg kde ldap libg++ mad midi mikmod mmx mmxext mono mp3 mpeg ncurses network nls nptl nptlonly ogg opengl oss pam pcre perl png ppds pppd python qt qt3 qt4 quicktime readline reflection samba sdl seamonkey session spell spl ssl svg tcpd test tetex tiff truetype truetype-fonts type1-fonts udev unicode usb vcd vorbis win32codecs x86 xine xinerama xml xorg xprint xv xvid zlib" ELIBC="glibc" INPUT_DEVICES="mouse keyboard" KERNEL="linux" LINGUAS="en de en_GB" USERLAND="GNU" VIDEO_CARDS="nv none"
Unset:  CTARGET, INSTALL_MASK, LC_ALL, LDFLAGS, MAKEOPTS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-02-11 10:33:52 UTC
x86 stable
Comment 5 Tobias Scherbaum (RETIRED) gentoo-dev 2007-02-11 11:04:39 UTC
ppc stable
Comment 6 Gustavo Zacarias (RETIRED) gentoo-dev 2007-02-12 13:55:49 UTC
sparc stable.
Comment 7 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-12 15:20:38 UTC
Thanks all,

security team (it's for the principle, because i know i'm alone) please vote for a GLSA or not
Comment 8 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-12 15:21:00 UTC
Hi Falco, i vote for NOglsa
Comment 9 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-12 22:31:56 UTC
(In reply to comment #8)
> Hi Falco, i vote for NOglsa
> 

Thanks Falco, let's close this bug then without any GLSA. Feel free to reopen if you disagree.