Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 40: 2024-2c564b942d Moderate: XSS Threats in php-wikimedia

fedora
Calendar Grey May 11, 2024
Dist Fedora Esm H88
Critical notice regarding Fedora 40 focused on php-wikimedia upgrades alongside security concerns related to XSS flaws.
https://www.mediawiki.org/wiki/Release_notes/1.41

Summary

utfnormal is a library that contains unicode normalization functions. It was

split out of MediaWiki core during the 1.25 development cycle.

Update Information:

https://www.mediawiki.org/wiki/Release_notes/1.41

Change Log

* Fri May 3 2024 Michael Cronenworth - 4.0.0-1 - version update

References


[ 1 ] Bug #2240808 - CVE-2023-3550 mediawiki: stored XSS leads to privilege escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2240808 [ 2 ] Bug #2241397 - mediawiki-1.41.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2241397 [ 3 ] Bug #2247804 - CVE-2023-45360 mediawiki: XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2247804 [ 4 ] Bug #2247806 - CVE-2023-45362 mediawiki: diff-multi-sameuser ("X intermediate revisions by the same user not shown") ignores username suppression [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2247806 [ 5 ] Bug #2255583 - CVE-2023-51704 mediawiki: group-.*-member messages are not properly escaped on Special:log/rights [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255583 [ 6 ] Bug #2261492 - php-oojs-oojs-ui: FTBFS in Fedora rawhide/f40 https://bugzilla.re...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2c564b942d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: php-wikimedia-utfnormal
Product: Fedora 40
Version: 4.0.0
Release: 1.fc40
Summary: Unicode normalization functions

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here