The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
References
Link | Resource |
---|---|
http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546 | Exploit |
http://moinmo.in/SecurityFixes | Vendor Advisory |
http://osvdb.org/48876 |
Configurations
Information
Published : 2009-03-29 18:30
Updated : 2009-03-29 21:00
NVD link : CVE-2008-6549
Mitre link : CVE-2008-6549
JSON object : View
CWE
Products Affected
moinmo
- moinmoin