Описание
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| moin | fixed | 1.9.1-1 | package | |
| moin | not-affected | lenny | package | |
| moin | not-affected | etch | package |
Примечания
http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2
http://hg.moinmo.in/moin/1.9/rev/04afdde50094
http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18
EPSS
Связанные уязвимости
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.
MoinMoin Exposure of Sensitive Disclosure when GATEWAY_INTERFACE variable is set
EPSS