On October 11th, Canonical published in a security notice details about MoinMoin vulnerabilities for its Ubuntu 12.04 LTS, Ubuntu 11.10, Ubuntu 11.04, and Ubuntu 10.04 LTS operating systems.
According to Canonical, Several security issues were fixed in MoinMoin.
LinuxSecurity.com: It was discovered that MoinMoin did not properly sanitize its input whenprocessing Despam actions, resulting in cross-site scripting (XSS)vulnerabilities. If a privileged wiki user were tricked into performingthe Despam action on a page with a crafted title, a remote attacker couldexploit this to execute JavaScript code. (CVE-2010-0828) [More...]
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that several wiki actions and preference settings in
MoinMoin were not protected from cross-site request forgery (CSRF). If an
authenticated user were tricked into visiting a malicious website while
logged into MoinMoin, a remote attacker could change the user's
MoinMoin: Multiple vulnerabilities
On January 29, Canonical published in a security notice details about an OpenStack Nova vulnerability for its Ubuntu 12.10, Ubuntu 12.04 LTS, and Ubuntu 11.10 operating systems.
According to Canonical, Nova volume could be made to expose volumes from other users.
It was discovered that nova-volume did not validate access to volumes.
I'd like to embed a cmap in a moinmoin wiki page. I generated the cmap using dia.
I then copy pasted the generated html code, modified it to point to the png image I attached to the wiki. However when saving the whole map section disappears from the code.
Does anyone has a pointer for me?
Canonical has published in a security notice details about an Emacs vulnerability for its Ubuntu 12.04 LTS and Ubuntu 11.10 operating systems.According to Canonical, Emacs could be made to run programs, as your login, if it opened a specially crafted file.Hiroshi Oota and Paul Ling discovered that the Emacs package incorrectly handled search paths and it incorrectly handled certain eval
LinuxSecurity.com: It was discovered the Samba handled symlinks in an unexpected way when both"wide links" and "UNIX extensions" were enabled, which is the default. Aremote attacker could create symlinks and access arbitrary files from theserver. [More...]
On October 3rd, in a security notice Canonical published details about a QEMU vulnerability for its Ubuntu 12.04 LTS, Ubuntu 11.10, Ubuntu 11.04, and Ubuntu 10.04 LTS operating systems.
According to Canonical, QEMU could have been made to crash or run programs. It was discovered that QEMU incorrectly handled certain VT100 escape sequences.