LWN.net Logo

moinmoin: privilege escalation

Package(s):moinmoin CVE #(s):CVE-2008-1937
Created:May 12, 2008 Updated:May 14, 2008
Description:

From the Gentoo advisory:

It has been reported that the user form processing in the file userform.py does not properly manage users when using Access Control Lists or a non-empty superusers list.

A remote attacker could exploit this vulnerability to gain superuser privileges on the application.

Alerts:
Gentoo 200805-09 2008-05-11

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds