MGASA-2015-0421
Dashboard / Vulnerabilities / MGASA-2015-0421
MGASA-2015-0421
Summary: Updated mediawiki packages fix security vulnerabilities
Details: Updated mediawiki packages fix security vulnerabilities: In MediaWiki before 1.23.11, the API failed to correctly stop adding new chunks to the upload when the reported size was exceeded, allowing a malicious user to upload add an infinite number of chunks for a single file upload (CVE-2015-8001). In MediaWiki before 1.23.11, a malicious user could upload chunks of 1 byte for very large files, potentially creating a very large number of files on the server's filesystem (CVE-2015-8002). In MediaWiki before 1.23.11, it is not possible to throttle file uploads, or in other words, rate limit them (CVE-2015-8003). In MediaWiki before 1.23.11, a missing authorization check when removing suppression from a revision allowed users with the 'viewsuppressed' user right but not the appropriate 'suppressrevision' user right to unsuppress revisions (CVE-2015-8004). In MediaWiki before 1.23.11, thumbnails of PNG files generated with ImageMagick contained the local file path in the image (CVE-2015-8005).
References: https://advisories.mageia.org/MGASA-2015-0421.html, https://bugs.mageia.org/show_bug.cgi?id=16990, https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html, http://openwall.com/lists/oss-security/2015/10/29/14
Affected packages
Package
Name: mediawiki
Purl: pkg:rpm/mageia/mediawiki?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
