<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Insanity Reviews Friends &#187; Python</title>
	<atom:link href="http://friends.insanity-reviews.com/tag/python/feed/" rel="self" type="application/rss+xml" />
	<link>http://friends.insanity-reviews.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Sat, 20 Nov 2010 07:20:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>USN-925-1: MoinMoin vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 22:20:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[1 April]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Moinmoin]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Python2]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>
		<category><![CDATA[Wiki]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0828, CVE-2010-1238        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-925-1             April 08, 2010
moin vulnerabilities
CVE-2010-0828, CVE-2010-1238
===========================================================
A security issue affects the [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0828, CVE-2010-1238        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-925-1             April 08, 2010<br />
moin vulnerabilities<br />
CVE-2010-0828, CVE-2010-1238<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 6.06 LTS<br />
Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 6.06 LTS:<br />
  python2.4-moinmoin              1.5.2-1ubuntu2.6</p>
<p>Ubuntu 8.04 LTS:<br />
  python-moinmoin                 1.5.8-5.1ubuntu2.4</p>
<p>Ubuntu 8.10:<br />
  python-moinmoin                 1.7.1-1ubuntu1.5</p>
<p>Ubuntu 9.04:<br />
  python-moinmoin                 1.8.2-2ubuntu2.3</p>
<p>Ubuntu 9.10:<br />
  python-moinmoin                 1.8.4-1ubuntu1.2</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>It was discovered that MoinMoin did not properly sanitize its input when<br />
processing Despam actions, resulting in cross-site scripting (XSS)<br />
vulnerabilities. If a privileged wiki user were tricked into performing<br />
the Despam action on a page with a crafted title, a remote attacker could<br />
exploit this to execute JavaScript code. (CVE-2010-0828)</p>
<p>It was discovered that the TextCha protection in MoinMoin could be bypassed<br />
by submitting a crafted form request. This issue only affected Ubuntu 8.10.<br />
(CVE-2010-1238)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/04/usn-925-1-moinmoin-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USN-911-1: MoinMoin vulnerabilities</title>
		<link>http://friends.insanity-reviews.com/2010/03/usn-911-1-moinmoin-vulnerabilities/</link>
		<comments>http://friends.insanity-reviews.com/2010/03/usn-911-1-moinmoin-vulnerabilities/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 09:20:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[911]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Csrf]]></category>
		<category><![CDATA[Edubuntu]]></category>
		<category><![CDATA[Forgery]]></category>
		<category><![CDATA[Malicious Content]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[March 11]]></category>
		<category><![CDATA[Moinmoin]]></category>
		<category><![CDATA[Nbsp]]></category>
		<category><![CDATA[Preference Settings]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Python2]]></category>
		<category><![CDATA[Security Issue]]></category>
		<category><![CDATA[Security Notice]]></category>
		<category><![CDATA[Usn]]></category>

		<guid isPermaLink="false">http://friends.insanity-reviews.com/2010/03/usn-911-1-moinmoin-vulnerabilities/</guid>
		<description><![CDATA[
Referenced CVEs:&#160;


                    CVE-2010-0668, CVE-2010-0669, CVE-2010-0717        



Description:&#160;



===========================================================
Ubuntu Security Notice USN-911-1             March 11, 2010
moin vulnerabilities
CVE-2010-0668, CVE-2010-0669, CVE-2010-0717
===========================================================
A security issue [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>Referenced CVEs:&nbsp;</div>
<div>
<div>
                    CVE-2010-0668, CVE-2010-0669, CVE-2010-0717        </div>
</p></div>
</div>
<div>
<div>Description:&nbsp;</div>
<div>
<div>
<div>
===========================================================<br />
Ubuntu Security Notice USN-911-1             March 11, 2010<br />
moin vulnerabilities<br />
CVE-2010-0668, CVE-2010-0669, CVE-2010-0717<br />
===========================================================</p>
<p>A security issue affects the following Ubuntu releases:</p>
<p>Ubuntu 6.06 LTS<br />
Ubuntu 8.04 LTS<br />
Ubuntu 8.10<br />
Ubuntu 9.04<br />
Ubuntu 9.10</p>
<p>This advisory also applies to the corresponding versions of<br />
Kubuntu, Edubuntu, and Xubuntu.</p>
<p>The problem can be corrected by upgrading your system to the<br />
following package versions:</p>
<p>Ubuntu 6.06 LTS:<br />
  python2.4-moinmoin              1.5.2-1ubuntu2.5</p>
<p>Ubuntu 8.04 LTS:<br />
  python-moinmoin                 1.5.8-5.1ubuntu2.3</p>
<p>Ubuntu 8.10:<br />
  python-moinmoin                 1.7.1-1ubuntu1.3</p>
<p>Ubuntu 9.04:<br />
  python-moinmoin                 1.8.2-2ubuntu2.2</p>
<p>Ubuntu 9.10:<br />
  python-moinmoin                 1.8.4-1ubuntu1.1</p>
<p>In general, a standard system upgrade is sufficient to effect the<br />
necessary changes.</p>
<p>Details follow:</p>
<p>It was discovered that several wiki actions and preference settings in<br />
MoinMoin were not protected from cross-site request forgery (CSRF). If an<br />
authenticated user were tricked into visiting a malicious website while<br />
logged into MoinMoin, a remote attacker could change the user&#8217;s<br />
configuration or wiki content. (CVE-2010-0668, CVE-2010-0717)</p>
<p>It was discovered that MoinMoin did not properly sanitize its input when<br />
processing user preferences. An attacker could enter malicious content<br />
which when viewed by a user, could render in unexpected ways.<br />
(CVE-2010-0669)
</p></div>
</p></div>
</p></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://friends.insanity-reviews.com/2010/03/usn-911-1-moinmoin-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

