Several vulnerabilities have been discovered in mediawiki, a web-based wiki
engine. The following issues have been identified:
Insufficient input sanitization in the CSS validation code allows editorsto display external images in wiki pages. This can be a privacy concern
on public wikis as it allows attackers to gather IP addresses and other
information by linking these images to a web server under their control.
Insufficient permission checks have been found in thump.php which can lead
to disclosure of image files that are restricted to certain users(e.g. with img_auth.php).
For the stable distribution (lenny), this problem has been fixed in
version 1.12.0-2lenny4.
For the testing distribution (squeeze), this problem has been fixed in
version 1:1.15.2-1.
For the unstable distribution (sid), this problem has been fixed in
version 1:1.15.2-1.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are u...
Get the latest Linux and open source security news straight to your inbox.