This service will be undergoing maintenance at 00:00 UTC, 2016-08-01. It is expected to last about 1 hours
Bug 482791 - (CVE-2009-0312) CVE-2009-0312 moin: XSS issue in antispam
CVE-2009-0312 moin: XSS issue in antispam
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
http://nvd.nist.gov/nvd.cfm?cvename=C...
impact=moderate,cwe=CWE-79[auto]
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-01-28 02:26 EST by Tomas Hoger
Modified: 2016-03-04 06:28 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Tomas Hoger 2009-01-28 02:26:51 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0312 to the following vulnerability:

Cross-site scripting (XSS) vulnerability in the antispam feature
(security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote
attackers to inject arbitrary web script or HTML via crafted,
disallowed content.

References:
http://moinmo.in/SecurityFixes#moin1.8.1
http://www.openwall.com/lists/oss-security/2009/01/27/4

Upstream commits (1.7.x and 1.8.x):
http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad
http://hg.moinmo.in/moin/1.8/rev/89b91bf87dad

Seems to affect 1.6.3 currently in Fedora too.
Comment 1 Fedora Update System 2009-04-20 11:18:52 EDT
moin-1.6.4-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/moin-1.6.4-1.fc10
Comment 2 Fedora Update System 2009-04-20 11:42:09 EDT
moin-1.6.4-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/moin-1.6.4-1.fc9
Comment 3 Fedora Update System 2009-04-21 21:04:04 EDT
moin-1.6.4-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2009-04-21 21:11:44 EDT
moin-1.6.4-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 5 Vincent Danen 2010-04-15 16:55:03 EDT
This looks to also affect moin 1.5.9 in EPEL4 and 5 (util/antispam.py).  Can this be corrected there as well?

Note You need to log in before you can comment on or make changes to this bug.