QID 997216
Date Published: 2024-02-12
QID 997216: Python (Pip) Security Update for moin (GHSA-wjjc-m3fc-fcm8)
The password_checker function in config/multiconfig.py in MoinMoin prior to version 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wjjc-m3fc-fcm8 for updates and patch information.
Vendor References
- GHSA-wjjc-m3fc-fcm8 -
github.com/advisories/GHSA-wjjc-m3fc-fcm8
CVEs related to QID 997216
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wjjc-m3fc-fcm8 | moin |
|