From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-201210-02.xml | 61 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 metadata/glsa/glsa-201210-02.xml (limited to 'metadata/glsa/glsa-201210-02.xml') diff --git a/metadata/glsa/glsa-201210-02.xml b/metadata/glsa/glsa-201210-02.xml new file mode 100644 index 000000000000..2953f4d5c318 --- /dev/null +++ b/metadata/glsa/glsa-201210-02.xml @@ -0,0 +1,61 @@ + + + + MoinMoin: Multiple vulnerabilities + Multiple vulnerabilities have been found in MoinMoin, the worst of + which allowing for injection of arbitrary web script or HTML. + + MoinMoin + 2012-10-18 + 2012-10-18: 1 + 305663 + 339295 + remote + + + 1.9.4 + 1.9.4 + + + +

MoinMoin is a Python WikiEngine.

+
+ +

Multiple vulnerabilities have been discovered in MoinMoin. Please review + the CVE identifiers referenced below for details. +

+
+ +

These vulnerabilities in MoinMoin allow remote users to inject arbitrary + web script or HTML, to obtain sensitive information and to bypass the + textcha protection mechanism. There are several other unknown impacts and + attack vectors. +

+ +
+ +

There is no known workaround at this time.

+
+ +

All MoinMoin users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-apps/moinmoin-1.9.4" + + +
+ + CVE-2010-0668 + CVE-2010-0669 + CVE-2010-0717 + CVE-2010-0828 + CVE-2010-1238 + CVE-2010-2487 + CVE-2010-2969 + CVE-2010-2970 + CVE-2011-1058 + + craig + craig +
-- cgit v1.2.3