LWN.net Logo

mediawiki: insecure file uploading

Package(s):mediawiki CVE #(s):CVE-2013-2114
Created:June 7, 2013 Updated:July 22, 2013
Description:

From the Red Hat bug report:

MediaWiki user Marco discovered that security checks for file uploads were not being run when the file was uploaded in chunks through the API. This option has been available to users who can upload files since MediaWiki 1.19.

Alerts:
Fedora FEDORA-2013-9622 2013-06-07
Fedora FEDORA-2013-9616 2013-06-07
Mageia MGASA-2013-0221 2013-07-21
Mageia MGASA-2013-0226 2013-07-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds