CVE-2010-0668
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.vupen.com/english/advisories/2010/0266
Vendor advisory: cve@mitre.org — http://www.securityfocus.com/bid/38023
Vendor advisory: cve@mitre.org — http://secunia.com/advisories/38709
Vendor advisory: cve@mitre.org — http://secunia.com/advisories/38444
Vendor advisory: cve@mitre.org — http://moinmo.in/SecurityFixes
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| moinmo | moinmoin | 1.5.0 | |
| moinmo | moinmoin | 1.5.1 | |
| moinmo | moinmoin | 1.5.2 | |
| moinmo | moinmoin | 1.5.3 | |
| moinmo | moinmoin | 1.5.4 | |
| moinmo | moinmoin | 1.5.5 | |
| moinmo | moinmoin | 1.5.5a | |
| moinmo | moinmoin | 1.5.6 | |
| moinmo | moinmoin | 1.5.7 | |
| moinmo | moinmoin | 1.5.8 | |
| moinmo | moinmoin | 1.6.0 | |
| moinmo | moinmoin | 1.6.1 | |
| moinmo | moinmoin | 1.6.2 | |
| moinmo | moinmoin | 1.6.3 | |
| moinmo | moinmoin | 1.6.4 | |
| moinmo | moinmoin | 1.7.0 | |
| moinmo | moinmoin | 1.7.1 | |
| moinmo | moinmoin | 1.7.2 | |
| moinmo | moinmoin | 1.7.3 | |
| moinmo | moinmoin | 1.8.0 | |
| moinmo | moinmoin | 1.8.1 | |
| moinmo | moinmoin | 1.8.2 | |
| moinmo | moinmoin | 1.8.3 | |
| moinmo | moinmoin | 1.8.4 | |
| moinmo | moinmoin | 1.8.6 | |
| moinmo | moinmoin | 1.9.0 | |
| moinmo | moinmoin | 1.9.1 | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-0668
- https://bugzilla.redhat.com/show_bug.cgi?id=565604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56002
- https://github.com/moinwiki/moin
- https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2010-15.yaml
- https://web.archive.org/web/20111225112846/http://secunia.com/advisories/38903
- https://web.archive.org/web/20140725192956/http://secunia.com/advisories/38709
- https://web.archive.org/web/20140806190238/http://secunia.com/advisories/38444
- https://web.archive.org/web/20200228174758/http://www.securityfocus.com/bid/38023
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975
- http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035374.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035438.html
- http://marc.info/?l=oss-security&m=126625972814888&w=2
- http://marc.info/?l=oss-security&m=126676896601156&w=2
- http://moinmo.in/MoinMoinRelease1.8
- http://moinmo.in/SecurityFixes
- http://www.debian.org/security/2010/dsa-2014
- http://www.openwall.com/lists/oss-security/2010/02/15/2
- http://secunia.com/advisories/38444
- http://secunia.com/advisories/38709
- http://secunia.com/advisories/38903
- http://www.osvdb.org/62043
- http://www.securityfocus.com/bid/38023
- http://www.vupen.com/english/advisories/2010/0266
Verify integrity in audit chain (admin only). AS-IS.