CVE-2007-2637: Medium severity Ubuntu Ubuntu Linux vulnerability
Published May 13, 2007
·Updated
MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.
Affected Software
9 affected componentsFixes available
pip/moin<1.5.8
1.5.8
All of the following
Any of the following
Ubuntu Ubuntu Linux=6.06_lts
Ubuntu Ubuntu Linux=6.10
Ubuntu Ubuntu Linux=7.04
MoinMoin MoinMoin<=1.5.7
Ubuntu Ubuntu Linux=6.06_lts
Ubuntu Ubuntu Linux=6.10
Ubuntu Ubuntu Linux=7.04
MoinMoin MoinMoin<=1.5.7
Remediation
Patch Available
Patch Available
Event History
May 13, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:19 PM
DescriptionWeaknessAffected Software
May 1, 2022
Advisory Published
via GitHub·06:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2007-2637?
CVE-2007-2637 has a moderate severity level as it allows unauthorized reading of pages due to insufficient ACL enforcement.
2
How do I fix CVE-2007-2637?
To fix CVE-2007-2637, upgrade MoinMoin to version 1.5.8 or higher.
3
What versions of MoinMoin are affected by CVE-2007-2637?
CVE-2007-2637 affects versions of MoinMoin up to 1.5.7.
4
Can Ubuntu Linux users be affected by CVE-2007-2637?
Ubuntu Linux systems using MoinMoin versions prior to 1.5.8 can be affected by CVE-2007-2637.
5
What type of attack does CVE-2007-2637 allow?
CVE-2007-2637 allows remote attackers to read certain pages through improper access control.