First published: Sun May 13 2007(Updated: )
MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/moin | <1.5.8 | 1.5.8 |
All of | ||
Any of | ||
Ubuntu Linux | =6.06_lts | |
Ubuntu Linux | =6.10 | |
Ubuntu Linux | =7.04 | |
Mastodon | <=1.5.7 | |
Ubuntu Linux | =6.06_lts | |
Ubuntu Linux | =6.10 | |
Ubuntu Linux | =7.04 | |
Mastodon | <=1.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2637 has a moderate severity level as it allows unauthorized reading of pages due to insufficient ACL enforcement.
To fix CVE-2007-2637, upgrade MoinMoin to version 1.5.8 or higher.
CVE-2007-2637 affects versions of MoinMoin up to 1.5.7.
Ubuntu Linux systems using MoinMoin versions prior to 1.5.8 can be affected by CVE-2007-2637.
CVE-2007-2637 allows remote attackers to read certain pages through improper access control.