SB2012100125 - Permissions, Privileges, and Access Controls in moinmoin (Alpine package)



SB2012100125 - Permissions, Privileges, and Access Controls in moinmoin (Alpine package)

Published: October 1, 2012

Security Bulletin ID SB2012100125
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-4404)

The vulnerability allows a remote #AU# to read and manipulate data.

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.


Remediation

Install update from vendor's website.