Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70578
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2366-1)
Summary:The remote host is missing an update for the Debian 'mediawiki' package(s) announced via the DSA-2366-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mediawiki' package(s) announced via the DSA-2366-1 advisory.

Vulnerability Insight:
Several problems have been discovered in MediaWiki, a website engine for collaborative work.

CVE-2011-1578 CVE-2011-1587 Masato Kinugawa discovered a cross-site scripting (XSS) issue, which affects Internet Explorer clients only, and only version 6 and earlier. Web server configuration changes are required to fix this issue. Upgrading MediaWiki will only be sufficient for people who use Apache with AllowOverride enabled. For details of the required configuration changes, see the upstream announcements.

CVE-2011-1579

Wikipedia user Suffusion of Yellow discovered a CSS validation error in the wikitext parser. This is an XSS issue for Internet Explorer clients, and a privacy loss issue for other clients since it allows the embedding of arbitrary remote images.

CVE-2011-1580

MediaWiki developer Happy-Melon discovered that the transwiki import feature neglected to perform access control checks on form submission. The transwiki import feature is disabled by default. If it is enabled, it allows wiki pages to be copied from a remote wiki listed in $wgImportSources. The issue means that any user can trigger such an import to occur.

CVE-2011-4360

Alexandre Emsenhuber discovered an issue where page titles on private wikis could be exposed bypassing different page ids to index.php. In the case of the user not having correct permissions, they will now be redirected to Special:BadTitle.

CVE-2011-4361

Tim Starling discovered that action=ajax requests were dispatched to the relevant function without any read permission checks being done. This could have led to data leakage on private wikis.

For the oldstable distribution (lenny), these problems have been fixed in version 1:1.12.0-2lenny9.

For the stable distribution (squeeze), these problems have been fixed in version 1:1.15.5-2squeeze2.

For the unstable distribution (sid), these problems have been fixed in version 1:1.15.5-5.

We recommend that you upgrade your mediawiki packages.

Affected Software/OS:
'mediawiki' package(s) on Debian 5, Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1578
44142
http://secunia.com/advisories/44142
47354
http://www.securityfocus.com/bid/47354
ADV-2011-0978
http://www.vupen.com/english/advisories/2011/0978
ADV-2011-1100
http://www.vupen.com/english/advisories/2011/1100
ADV-2011-1151
http://www.vupen.com/english/advisories/2011/1151
DSA-2366
http://www.debian.org/security/2011/dsa-2366
FEDORA-2011-5495
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.html
FEDORA-2011-5807
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html
FEDORA-2011-5812
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html
FEDORA-2011-5848
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html
[mediawiki-announce] 20110412 MediaWiki security release 1.16.3
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000096.html
[oss-security] 20110413 Re: CVE request: mediawiki 1.16.3
http://openwall.com/lists/oss-security/2011/04/13/15
https://bugzilla.redhat.com/show_bug.cgi?id=695577
https://bugzilla.redhat.com/show_bug.cgi?id=696360
https://bugzilla.wikimedia.org/show_bug.cgi?id=28235
mediawiki-file-extensions-xss(66737)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66737
Common Vulnerability Exposure (CVE) ID: CVE-2011-1579
http://www.mediawiki.org/wiki/Special:Code/MediaWiki/85856
https://bugzilla.wikimedia.org/show_bug.cgi?id=28450
mediawiki-css-data-xss(66738)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66738
Common Vulnerability Exposure (CVE) ID: CVE-2011-1580
https://bugzilla.wikimedia.org/show_bug.cgi?id=28449
mediawiki-transwiki-sec-bypass(66739)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66739
Common Vulnerability Exposure (CVE) ID: CVE-2011-1587
[mediawiki-announce] 20110414 MediaWiki security release 1.16.4
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-April/000097.html
[oss-security] 20110418 Re: CVE request: mediawiki 1.16.4, incomplete fix of CVE-2011-1578
http://openwall.com/lists/oss-security/2011/04/18/5
Common Vulnerability Exposure (CVE) ID: CVE-2011-4360
[mediawiki-announce] 20111128 MediaWiki security release 1.17.1
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html
[oss-security] 20111129 CVE request: mediawiki before 1.17.1
http://openwall.com/lists/oss-security/2011/11/29/6
[oss-security] 20111129 Re: CVE request: mediawiki before 1.17.1
http://openwall.com/lists/oss-security/2011/11/29/12
https://bugzilla.redhat.com/show_bug.cgi?id=758171
https://bugzilla.wikimedia.org/show_bug.cgi?id=32276
Common Vulnerability Exposure (CVE) ID: CVE-2011-4361
https://bugzilla.wikimedia.org/show_bug.cgi?id=32616
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.