CVE-2010-0668: Medium severity MoinMoin vulnerability
Multiple security issues have been reported in Moin: [1] http://moinmo.in/SecurityFixes [2] http://secunia.com/advisories/38444/
Upstream Moin v1.8.7 version was released: [3] http://moinmo.in/
Addressing "major security issues in miscellaneous parts of moin.": [4] http://moinmo.in/MoinMoinRelease1.8 [5] http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES
CVE Request: [6] http://www.openwall.com/lists/oss-security/2010/02/15/2
Other references: [7] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975
As mentioned in [7]: "<ThomasWaldmann> 2) it's not just a single patch, it is quite much, you don't want to apply them manually. if you need it now, do a repo checkout and you'll have 1.9.2pre kind of"
Other sources
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0668?
The severity of CVE-2010-0668 is unknown as the impact and attack vectors are unspecified.
How do I fix CVE-2010-0668?
To fix CVE-2010-0668, upgrade MoinMoin to version 1.8.7 or greater if using versions 1.5.x to 1.7.x or to 1.9.2 or greater if using 1.9.x.
Which versions of MoinMoin are affected by CVE-2010-0668?
MoinMoin versions 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 are affected.
Can I be attacked if I have a non-empty superuser list with CVE-2010-0668?
Yes, having a non-empty superuser list may expose you to risks related to CVE-2010-0668.
Is the xmlrpc action related to CVE-2010-0668 vulnerabilities?
Yes, enabling the xmlrpc action in MoinMoin is one of the configurations that contributes to the vulnerability identified in CVE-2010-0668.