CVE-2008-6549: High severity MoinMoin vulnerability
The passwordchecker function in config/multiconfig.py in MoinMoin prior to version 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
Other sources
The passwordchecker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/mointo a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6549?
CVE-2008-6549 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2008-6549?
To fix CVE-2008-6549, upgrade MoinMoin to version 1.6.1 or later.
What versions of MoinMoin are affected by CVE-2008-6549?
CVE-2008-6549 affects all versions of MoinMoin prior to 1.6.1.
What component of MoinMoin is vulnerable in CVE-2008-6549?
The vulnerability in CVE-2008-6549 resides in the password_checker function in config/multiconfig.py.
Can CVE-2008-6549 be exploited remotely?
Yes, CVE-2008-6549 can be exploited remotely to cause a denial of service.