MGASA-2013-0368
Dashboard / Vulnerabilities / MGASA-2013-0368
MGASA-2013-0368
Summary: Updated mediawiki packages fix security vulnerabilities
Details: Updated mediawiki packages fix security vulnerabilities: Kevin Israel (Wikipedia user PleaseStand) identified and reported two vectors for injecting Javascript in CSS that bypassed MediaWiki's blacklist (CVE-2013-4567, CVE-2013-4568). Internal review while debugging a site issue discovered that MediaWiki and the CentralNotice extension were incorrectly setting cache headers when a user was autocreated, causing the user's session cookies to be cached, and returned to other users (CVE-2013-4572).
References: https://advisories.mageia.org/MGASA-2013-0368.html, http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.html, https://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.html, https://bugs.mageia.org/show_bug.cgi?id=11854
Affected packages
Package
Name: mediawiki
Purl: pkg:rpm/mageia/mediawiki?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
