The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
References
Link | Resource |
---|---|
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Exploit |
http://moinmo.in/SecurityFixes | Vendor Advisory |
http://osvdb.org/48876 | |
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Exploit |
http://moinmo.in/SecurityFixes | Vendor Advisory |
http://osvdb.org/48876 |
Configurations
History
21 Nov 2024, 00:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 - Exploit | |
References | () http://moinmo.in/SecurityFixes - Vendor Advisory | |
References | () http://osvdb.org/48876 - |
Information
Published : 2009-03-30 01:30
Updated : 2024-11-21 00:56
NVD link : CVE-2008-6549
Mitre link : CVE-2008-6549
CVE.ORG link : CVE-2008-6549
JSON object : View
Products Affected
moinmo
- moinmoin
CWE