GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Wed Jul 20, 2005 8:00 am Post subject: [ GLSA 200507-18 ] MediaWiki: Cross-site scripting vulnerabi |
|
|
Gentoo Linux Security Advisory
Title: MediaWiki: Cross-site scripting vulnerability (GLSA 200507-18)
Severity: low
Exploitable: remote
Date: July 20, 2005
Updated: August 11, 2005
Bug(s): #99132
ID: 200507-18
Synopsis
MediaWiki is vulnerable to a cross-site scripting attack that could allow arbitrary JavaScript code execution.
Background
MediaWiki is a collaborative editing software, used by big projects like Wikipedia.
Affected Packages
Package: www-apps/mediawiki
Vulnerable: < 1.4.6
Unaffected: >= 1.4.6
Architectures: All supported architectures
Description
MediaWiki fails to escape a parameter in the page move template correctly.
Impact
By enticing a user to visit a specially crafted URL, a remote attacker could exploit this vulnerability to inject malicious JavaScript code that will be executed in a user's browser session in the context of the vulnerable site.
Workaround
There is no known workaround at this time.
Resolution
All MediaWiki users should upgrade to the latest available version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.4.7" |
References
CAN-2005-2396
MediaWiki Release Notes
Last edited by GLSA on Mon Aug 14, 2006 4:16 am; edited 3 times in total |
|