SB2012100125 - Permissions, Privileges, and Access Controls in moinmoin (Alpine package)
Published: October 1, 2012
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-4404)
The vulnerability allows a remote #AU# to read and manipulate data.
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Remediation
Install update from vendor's website.