Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DSA-1901-1 Critical Mediawiki1.7: Cross-Site Threat

debian
Calendar Grey October 5, 2009
Debian Logo
Important security notice regarding MediaWiki version 1.7, highlighting multiple vulnerabilities; immediate update is advised.
Several vulnerabilities have been discovered in mediawiki1.7, a website engine for collaborative work

Summary

Several vulnerabilities have been discovered in mediawiki1.7, a website engine
for collaborative work. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2008-5249

David Remahl discovered that mediawiki1.7 is prone to a cross-site scripting attack.

CVE-2008-5250

David Remahl discovered that mediawiki1.7, when Internet Explorer is used and
uploads are enabled, or an SVG scripting browser is used and SVG uploads are
enabled, allows remote authenticated users to inject arbitrary web script or
HTML by editing a wiki page.

CVE-2008-5252

David Remahl discovered that mediawiki1.7 is prone to a cross-site request
forgery vulnerability in the Special:Import feature.

CVE-2009-0737

It was discovered that mediawiki1.7 is prone to a cross-site scripting attack in
the web-based installer.


For the oldstable distribution (etch), these problems have been fixed in version
1.7.1-9etch1 for mediawiki1.7, and mediawiki is not affected (it is a
metapackage for mediawiki1.7).

The stable ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mediawiki1.7
CVE IDs: CVE-2008-5249 CVE-2008-5250 CVE-2008-5252 CVE-2009-0737

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here