MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
BID:10801
Info
MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
| Bugtraq ID: | 10801 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2004 12:00AM |
| Updated: | Jul 26 2004 12:00AM |
| Credit: | Discovery is credited to Dr. Pleger. |
| Vulnerable: |
MoinMoin MoinMoin 1.2.2 |
| Not Vulnerable: |
MoinMoin MoinMoin 1.2.3 |
Discussion
MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
MoinMoin is reported prone to an unspecified privilege escalation vulnerability. This issue is related to the PageEditor functionality. Specifically this vulnerability may arise due to improper implementation of access control lists. A remote attacker may exploit this to gain elevated privileges.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
This issues is identified in MoinMoin version 1.2.2, however, other versions may be affected as well.
MoinMoin is reported prone to an unspecified privilege escalation vulnerability. This issue is related to the PageEditor functionality. Specifically this vulnerability may arise due to improper implementation of access control lists. A remote attacker may exploit this to gain elevated privileges.
Due to a lack of details, further information is not available at the moment. This BID will be updated as more information becomes available.
This issues is identified in MoinMoin version 1.2.2, however, other versions may be affected as well.
Exploit / POC
MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
Solution:
The vendor has released MoinMoin version 1.2.3 to address this issue.
Gentoo has released an advisory (GLSA 200408-25) to address issues in MoinMoin. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-ww/moinmoin-1.2.3"
emerge ">=net-ww/moinmoin-1.2.3"
MoinMoin MoinMoin 1.2.2
Solution:
The vendor has released MoinMoin version 1.2.3 to address this issue.
Gentoo has released an advisory (GLSA 200408-25) to address issues in MoinMoin. Please see the referenced advisory for more information. Gentoo users can carry out the following commands to update their computers:
emerge sync
emerge -pv ">=net-ww/moinmoin-1.2.3"
emerge ">=net-ww/moinmoin-1.2.3"
MoinMoin MoinMoin 1.2.2
-
MoinMoin moin-1.2.3.tar.gz
http://prdownloads.sourceforge.net/moin/moin-1.2.3.tar.gz?download
References
MoinMoin PageEditor Unspecified Privilege Escalation Vulnerability
References:
References:
- MoinMoin Homepage (MoinMoin)
- MoinMoin: Release Notes (MoinMoin)