Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: DSA-2022-1 Moderate: MediaWiki Remote Disclosure Threat

debian
Calendar Grey March 23, 2010
Debian Logo
The Debian Security Notice DSA-2022-1 outlines multiple vulnerabilities in mediawiki that could affect the confidentiality and safety of user information.
Several vulnerabilities have been discovered in mediawiki, a web-based wiki engine

Summary

Several vulnerabilities have been discovered in mediawiki, a web-based wiki
engine. The following issues have been identified:

Insufficient input sanitization in the CSS validation code allows editorsto display external images in wiki pages. This can be a privacy concern
on public wikis as it allows attackers to gather IP addresses and other
information by linking these images to a web server under their control.

Insufficient permission checks have been found in thump.php which can lead
to disclosure of image files that are restricted to certain users(e.g. with img_auth.php).


For the stable distribution (lenny), this problem has been fixed in
version 1.12.0-2lenny4.

For the testing distribution (squeeze), this problem has been fixed in
version 1:1.15.2-1.

For the unstable distribution (sid), this problem has been fixed in
version 1:1.15.2-1.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are u...

Read the Full Advisory

Package: mediawiki
CVE ID: none assigned yet

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here