mediawiki: multiple vulnerabilities
| Package(s): | mediawiki | CVE #(s): | CVE-2011-1587 CVE-2011-4360 CVE-2011-4361 | ||||
| Created: | December 19, 2011 | Updated: | December 21, 2011 | ||||
| Description: | From the Debian advisory:
CVE-2011-1587: Masato Kinugawa discovered a cross-site scripting (XSS) issue, which affects Internet Explorer clients only, and only version 6 and earlier. Web server configuration changes are required to fix this issue. Upgrading MediaWiki will only be sufficient for people who use Apache with AllowOverride enabled. CVE-2011-4360: Alexandre Emsenhuber discovered an issue where page titles on private wikis could be exposed bypassing different page ids to index.php. In the case of the user not having correct permissions, they will now be redirected to Special:BadTitle. CVE-2011-4361: Tim Starling discovered that action=ajax requests were dispatched to the relevant function without any read permission checks being done. This could have led to data leakage on private wikis. | ||||||
| Alerts: |
| ||||||
