LWN.net Logo

mediawiki: multiple vulnerabilities

Package(s):mediawiki CVE #(s):CVE-2013-2031 CVE-2013-2032
Created:May 20, 2013 Updated:May 22, 2013
Description: From the Red Hat bugzilla:

Two flaws were corrected in the recently-released MediaWiki 1.20.5 and 1.19.6 releases:

* Jan Schejbal / Hatforce.com reported that SVG script filtering could be bypassed for Chrome and Firefox clients by using an encoding that MediaWiki understood, but these browsers interpreted as UTF-8. [1]

* Internal review discovered that extensions were not given the opportunity to disable a password reset, which could lead to circumvention of two-factor authentication. [2]

[1] https://bugzilla.wikimedia.org/show_bug.cgi?id=47304
[2] https://bugzilla.wikimedia.org/show_bug.cgi?id=46590

Alerts:
Fedora FEDORA-2013-7714 2013-05-19
Fedora FEDORA-2013-7701 2013-05-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds