MoinMoin的组名权限提升漏洞

漏洞信息详情

MoinMoin的组名权限提升漏洞

漏洞简介

MoinMoin 1.2.1以及之前的版本存在漏洞。远程攻击者可以通过创建一个与现有组名称相同具有更高权限的用户提升特权。

漏洞公告

Gentoo has released an advisory with updates to address this issue. Updates may be applied with the following commands:
emerge sync
emerge -pv “>=net-ww/moinmoin-1.2.2”
emerge “>=net-ww/moinmoin-1.2.2”
The released version 1.2.2 does not reportedly contain this vulnerability. Users of affected packages are urged to upgrade.

参考网址

来源: BID
名称: 10568
链接:http://www.securityfocus.com/bid/10568

来源: GENTOO
名称: GLSA-200407-09
链接:http://www.gentoo.org/security/en/glsa/glsa-200407-09.xml

来源: XF
名称: moinmoin-gain-admin-access(16465)
链接:http://xforce.iss.net/xforce/xfdb/16465

来源: OSVDB
名称: 6704
链接:http://www.osvdb.org/6704

来源: sourceforge.net
链接:http://sourceforge.net/tracker/index.php?func=detail&aid=948103&group_id=8482&atid=108482

来源: SECUNIA
名称: 11807
链接:http://secunia.com/advisories/11807

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享