Oval Definition:oval:org.mitre.oval:def:7451
Revision Date:2015-02-23Version:21
Title:DSA-2022 mediawiki -- several vulnerabilities
Description:Several vulnerabilities have been discovered in mediawiki, a web-based wiki engine. The following issues have been identified: Insufficient input sanitisation in the CSS validation code allows editors to display external images in wiki pages. This can be a privacy concern on public wikis as it allows attackers to gather IP addresses and other information by linking these images to a web server under their control. Insufficient permission checks have been found in thump.php which can lead to disclosure of image files that are restricted to certain users .
Family:unixClass:patch
Status:ACCEPTEDReference(s):DSA-2022
Platform(s):Debian GNU/Linux 5.0
Product(s):mediawiki
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND mediawiki is earlier than 1:1.12.0-2lenny4
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND mediawiki-math is earlier than 1:1.12.0-2lenny4
  • BACK