Описание
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | not-affected | code not present |
| devel | not-affected | 1.8.2-2ubuntu2 |
| gutsy | ignored | end of life, was needed |
| hardy | not-affected | code not present |
| intrepid | not-affected | 1.7.1-1ubuntu1.1 |
| jaunty | not-affected | 1.8.2-2ubuntu2 |
| upstream | released | 1.6.2 |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
Связанные уязвимости
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
The password_checker function in config/multiconfig.py in MoinMoin 1.6 ...
MoinMoin Denial of Service vulnerability via password_checker function
EPSS
5 Medium
CVSS2