Joined: 12 May 2004
|Posted: Tue Apr 04, 2006 12:26 pm Post subject: [ GLSA 200604-01 ] MediaWiki: Cross-site scripting vulnerabi
|Gentoo Linux Security Advisory
Title: MediaWiki: Cross-site scripting vulnerability (GLSA 200604-01)
Date: April 04, 2006
MediaWiki is a collaborative editing software, used by big projects like Wikipedia.
Vulnerable: < 1.4.15
Unaffected: >= 1.4.15
Architectures: All supported architectures
MediaWiki fails to decode certain encoded URLs correctly.
There is no known workaround at this time.
All MediaWiki users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.4.15"
MediaWiki 1.4.15 Release Notes
Last edited by GLSA on Sun May 07, 2006 5:00 pm; edited 1 time in total