GHSA-wjjc-m3fc-fcm8
Dashboard / Vulnerabilities / GHSA-wjjc-m3fc-fcm8
GHSA-wjjc-m3fc-fcm8
Summary: MoinMoin Denial of Service vulnerability via password_checker function
Details: The password_checker function in `config/multiconfig.py` in MoinMoin prior to version 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2008-6549, https://github.com/moinwiki/moin, https://github.com/pypa/advisory-database/tree/main/vulns/moin/PYSEC-2009-12.yaml, https://web.archive.org/web/20080410051007/http://moinmo.in/SecurityFixes, https://web.archive.org/web/20211206185024/http://hg.moinmo.in/moin/1.6/rev/35ff7a9b1546
Affected packages
Package
Name: moin
Purl: pkg:pypi/moin
Affected ranges
Type: ECOSYSTEM
Events:
