Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 6: MGASA-2018-0433 Moderate: Mediawiki Account Bypass

mageia
Calendar Grey November 3, 2018
Dist Mageia Esm H88
Updated Mediawiki packages address various security vulnerabilities in Mageia, impacting account and logging data.
Updated mediawiki packages fix security vulnerabilities: '$wgRateLimits' entry for 'user' overrides 'newbie' (CVE-2018-0503)

Summary

Updated mediawiki packages fix security vulnerabilities:
'$wgRateLimits' entry for 'user' overrides 'newbie' (CVE-2018-0503).
When a log event is (partially) hidden Special:Redirect/logid can link to the incorrect log and reveal hidden information (CVE-2018-0504).
BotPasswords can bypass CentralAuth's account lock (CVE-2018-0505).

References

- https://bugs.mageia.org/show_bug.cgi?id=23662

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/LEXZ2QALRATNRZBLFXYWCIJH4G5S2L3T/

- https://www.cve.org/CVERecord?id=CVE-2018-0503

- https://www.cve.org/CVERecord?id=CVE-2018-0504

- https://www.cve.org/CVERecord?id=CVE-2018-0505

Resolution

SRPMS

- 6/core/mediawiki-1.27.5-1.mga6

Publication date: 03 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0433.html
Type: security
CVE: CVE-2018-0503, CVE-2018-0504, CVE-2018-0505

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here