Name | CVE-2010-0667 |
Description | MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
moin | source | etch | (not affected) | |||
moin | source | lenny | (not affected) | |||
moin | source | (unstable) | 1.9.1-1 |
[lenny] - moin <not-affected> (versions before 1.9 are not affected)
[etch] - moin <not-affected> (versions before 1.9 are not affected)
http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2
http://hg.moinmo.in/moin/1.9/rev/04afdde50094
http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18