CVE-2009-4762

NameCVE-2009-4762
DescriptionMoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs569975

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
moin (PTS)jessie1.9.8-1+deb8u1fixed
jessie (security)1.9.8-1+deb8u2fixed
buster, sid, stretch (security), stretch1.9.9-1+deb9u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
moinsource(unstable)1.9.2-1medium569975
moinsourcelenny1.7.1-3+lenny3medium569975

Notes

see http://www.debian.org/security/2010/dsa-2014

Search for package or bug name: Reporting problems