MGASA-2014-0253
Dashboard / Vulnerabilities / MGASA-2014-0253
Summary: Updated mediawiki packages fix security vulnerability
Details: XSS vulnerability in MediaWiki before 1.22.7, due to usernames on Special:PasswordReset being parsed as wikitext. The username on Special:PasswordReset can be supplied by anyone and will be parsed with wgRawHtml enabled. Since Special:PasswordReset is whitelisted by default on private wikis, this could potentially lead to an XSS crossing a privilege boundary (CVE-2014-3966).
References: https://advisories.mageia.org/MGASA-2014-0253.html, https://bugs.mageia.org/show_bug.cgi?id=13477, https://bugzilla.wikimedia.org/show_bug.cgi?id=65501, http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-May/000151.html, http://openwall.com/lists/oss-security/2014/06/04/15
Affected packages
Package
Name: mediawiki
Purl: pkg:rpm/mageia/mediawiki?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
