MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2010/02/15/2 | mailing list |
http://moinmo.in/SecurityFixes | vendor advisory |
http://hg.moinmo.in/moin/1.9/rev/04afdde50094 | |
http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18 | |
http://marc.info/?l=oss-security&m=126676896601156&w=2 | mailing list |
http://www.openwall.com/lists/oss-security/2010/01/21/6 | mailing list |
http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2 | |
http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES | |
http://marc.info/?l=oss-security&m=126625972814888&w=2 | mailing list |
http://secunia.com/advisories/38242 | third party advisory vendor advisory |