Your message dated Wed, 28 Jan 2009 17:17:31 +0000
with message-id <e1lse2d-00061b...@ries.debian.org>
and subject line Bug#513158: fixed in moin 1.8.1-1.1
has caused the Debian Bug report #513158,
regarding CVE-2009-0260: Multiple cross-site scripting vulnerabilities
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
513158: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513158
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: python-moinmoin
Severity: grave
Tags: security, patch
Justification: user security hole

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for moin.

CVE-2009-0260[0]:
| Multiple cross-site scripting (XSS) vulnerabilities in
| action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers
| to inject arbitrary web script or HTML via an AttachFile action to the
| WikiSandBox component with (1) the rename parameter or (2) the drawing
| parameter (aka the basename variable).

The upstream patch can be found here[1]. Please note that despite the
CVE description, version 1.8.1 in sid is still vulnerable.

Also, I haven't looked at the attack vector yet, but if we end up fixing
this for stable as well, we should adjust the wikiutil.escape function
to also take care of single quotes "'".
However, the patch should be trivial as well.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

Cheers
Steffen

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0260
    http://security-tracker.debian.net/tracker/CVE-2009-0260
[1] http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1



--- End Message ---
--- Begin Message ---
Source: moin
Source-Version: 1.8.1-1.1

We believe that the bug you reported is fixed in the latest version of
moin, which is due to be installed in the Debian FTP archive:

moin_1.8.1-1.1.diff.gz
  to pool/main/m/moin/moin_1.8.1-1.1.diff.gz
moin_1.8.1-1.1.dsc
  to pool/main/m/moin/moin_1.8.1-1.1.dsc
python-moinmoin_1.8.1-1.1_all.deb
  to pool/main/m/moin/python-moinmoin_1.8.1-1.1_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 513...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steffen Joeris <wh...@debian.org> (supplier of updated moin package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 28 Jan 2009 02:34:32 +0100
Source: moin
Binary: python-moinmoin
Architecture: source all
Version: 1.8.1-1.1
Distribution: unstable
Urgency: high
Maintainer: Jonas Smedegaard <d...@jones.dk>
Changed-By: Steffen Joeris <wh...@debian.org>
Description: 
 python-moinmoin - Python clone of WikiWiki - library
Closes: 513158
Changes: 
 moin (1.8.1-1.1) unstable; urgency=high
 .
   * Non-maintainer upload by the security team
   * Fix cross-site scripting vulnerability via basename parameter in the
     AttachFile action (Closes: #513158)
     Fixes: CVE-2009-0260
   * Fix cross-site scripting vulnerability in antispam.py via malformed
     content
     Fixes: CVE-2009-0312
Checksums-Sha1: 
 aee88055ccc086554a96d65774ac51fea05fcb71 1238 moin_1.8.1-1.1.dsc
 16101e2d73cba551a4e663f222063cabe5f93d78 94143 moin_1.8.1-1.1.diff.gz
 ef511ecde30e71e46e362bb279ed4dbf2c2a4e8e 5025896 
python-moinmoin_1.8.1-1.1_all.deb
Checksums-Sha256: 
 d409a652ee31aaaa371fbd526f85885ad18d00131b314676eba1c058097520a3 1238 
moin_1.8.1-1.1.dsc
 e7a6796a48ecea3547c4d38edf0d14c9ce1993f23c91a57bd383d1b765fc3f83 94143 
moin_1.8.1-1.1.diff.gz
 51dfdcb5be236d374834c5358081b666363a4ed82cd8957be029f6af75cc09f3 5025896 
python-moinmoin_1.8.1-1.1_all.deb
Files: 
 cf8dcce3b2fc193300d7be768d4600e4 1238 net optional moin_1.8.1-1.1.dsc
 8988e5abb7fe89cd57f12ec08083c043 94143 net optional moin_1.8.1-1.1.diff.gz
 bb509194439b32b0457f29d0c5caba34 5025896 python optional 
python-moinmoin_1.8.1-1.1_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkmAjvEACgkQ62zWxYk/rQe/lQCePc4XcWZlUsKJTjm1GeMGMAR0
maAAn2VbVE7qz9ENCKLQp8ivT0kuiYXp
=QHtk
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to