Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 170866 - www-apps/moinmoin Incomplete fix for CVE-2007-0857
Summary: www-apps/moinmoin Incomplete fix for CVE-2007-0857
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard: B4 [noglsa] Falco
Keywords:
Depends on: 177604
Blocks:
  Show dependency tree
 
Reported: 2007-03-14 13:09 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-07-23 15:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-14 13:09:50 UTC
"Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 
1.5.7 allow remote attackers to inject arbitrary web script or HTML via 
(1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, 
or (4) LocalSiteMap action."

The upstream changes are visible here:
http://hg.thinkmo.de/moin/1.5?fl=28eb59256911;file=docs/CHANGES

However, LikePages was missed, and the upstream LocalSiteMap fix appears 
to be incomplete.  Attached is the patch I'm using in Ubuntu.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-03-25 06:57:05 UTC
Issue was reported by Kees Cook.

web-apps please advise.
Comment 2 Renat Lumpau (RETIRED) gentoo-dev 2007-05-28 00:53:47 UTC
is this fixed properly in 1.5.8?
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-28 06:22:08 UTC
moin-1.5.7/debian/patches/00829_SECURITY_FIX_XSS_in_AttachFile_do_parameter.patch seems to have been applied in 1.5.8 so I would say so.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-28 06:36:33 UTC
Let's handle stable marking of 1.5.8 on bug #177604
Comment 5 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-23 15:03:30 UTC
Seems that we had forgotten this one :)
Now that 1.5.8 is stable, it's time for glsa decision. I vote NO.
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-07-23 15:12:04 UTC
Voting NO and closing.