Date: Mon, 15 Feb 2010 18:44:42 +0100 From: Jan Lieskovsky <jlieskov@...hat.com> To: oss-security <oss-security@...ts.openwall.com> CC: "Steven M. Christey" <coley@...us.mitre.org>, Thomas Waldmann <tw-public@....de> Subject: CVE Request -- MoinMoin -- 1.8.7 Hi Steve, vendors, multiple security issues have been reported against different versions of MoinMoin -- complete list here:  http://moinmo.in/SecurityFixes (part moin 1.9.1) Yesterday (2010-02-14) MoinMoin-1.8.7 was released:  http://moinmo.in/ fixing "major security issues in miscellaneous parts of moin":  http://moinmo.in/MoinMoinRelease1.8  http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES From what I can tell, when mapping  to  the: a, "A major security issue was discovered that could affect all moin versions 1.5.0 up to and including 1.9.1. For now, you can avoid the issue by not having any user names in your superuser list" was fixed. b, "Exclude (disable) xmlrpc and SyncPages actions" -- this was 'only' disabled -- "Improved package security: cfg.packagepages_actions_excluded excludes unsafe or otherwise questionable package actions by default now.". Though there are xmlrpc related fixes in 1.8.7: "xmlrpc: * Process attachname in get/putAttachment similarly. * revertPage: convert pagename to internal representation." -- Thomas are these also security related fixes? c, " Do not use OpenID auth code" -- not sure about state of this. Also, Changes file for MoinMoin 1.9.1 mentions:  http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES d, "* Fixed sys.argv security issue." -- not sure, if this is v1.9.1 specific or affects also prior versions of MoinMoin. Other references:  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975 Last message in:  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975#10 suggests only the "superuser list" issue was fixed in 1.8.7 and more fixes are about to come -- "<ThomasWaldmann> 1.9.2 planned in about 1 or 2 weeks". Cc-ed Thomas Waldmann on this post, so he can detail what was fixed to know, how many CVE identifiers are needed / sufficient for MoinMoin of version v.1.8.7. Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.