Package: python-moinmoin
Version: 1.7.1-3+lenny4
Severity: important
Tags: patch


Hallo,

python-moinmoin search fails to detect https correctly when running
under mod_wsgi. This problem is known upstream:
http://moinmo.in/MoinMoinBugs/TitleSearchFailsWsgiSSL

There is a security implication of this bug: in a https only environment
information about a wiki instance is sent unencrypted over network. 

A fix is available for quite a while:
http://hg.moinmo.in/moin/1.7/rev/3e019f6ae381

greetings,
rupi

-- System Information:
Debian Release: 5.0.4
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-2-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages python-moinmoin depends on:
ii  python                       2.5.2-3     An interactive high-level object-o
ii  python-support               0.8.4lenny1 automated rebuilding support for P

Versions of packages python-moinmoin recommends:
ii  postfix [mail-transport-agent 2.5.5-1.1  High-performance mail transport ag
ii  python-xapian                 1.0.7-3.1  Xapian search engine interface for
pn  python-xml                    <none>     (no description available)

Versions of packages python-moinmoin suggests:
pn  antiword                 <none>          (no description available)
ii  apache2                  2.2.9-10+lenny7 Apache HTTP Server metapackage
ii  apache2-mpm-worker [http 2.2.9-10+lenny7 Apache HTTP Server - high speed th
pn  catdoc                   <none>          (no description available)
pn  python-4suite-xml        <none>          (no description available)
pn  python-docutils          <none>          (no description available)
pn  python-gdchart           <none>          (no description available)
pn  python-pyxmpp            <none>          (no description available)
ii  wamerican [wordlist]     6-2.3           American English dictionary words 

-- no debconf information





-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to