Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 59338

Summary: net-www/moinmoin-1.2.3 Fixes security issues
Product: Gentoo Security Reporter: Sune Kloppenborg Jeppesen (RETIRED) <jaervosz>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://www.securityfocus.com/bid/10805
Whiteboard: B3? [ ebuild ] jaervosz
Package list:
Runtime testing required: ---

Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-03 23:19:36 UTC
From ChangeLog:

-ACL security fix for PageEditor, thanks to Dr. Pleger for reporting
-There was a bad, old bug that triggered if you did not use ACLs. In that
      case, moin used some simple (but wrong and incomplete) function to
      determine what a user (or bot) may do or may not do. The function is now
      fixed to allow only read and write to anon users, and only delete and
      revert to known users additionally - and disallow everything else.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-08-03 23:21:48 UTC
web-apps please bump to latest version.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2004-08-04 00:33:29 UTC

*** This bug has been marked as a duplicate of 57913 ***