Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 207757 - www-apps/mediawiki Cross-Site Scripting Vulnerability (CVE-2008-0460)
Summary: www-apps/mediawiki Cross-Site Scripting Vulnerability (CVE-2008-0460)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/28629
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-01-27 21:42 UTC by Lars Hartmann
Modified: 2008-02-25 22:11 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2008-01-27 21:42:53 UTC
A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via unspecified parameters to api.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The vulnerability affects users of Microsoft Internet Explorer only.

Successful exploitation requires that the API interface is enabled.

The vulnerability is reported in the following versions:
* 1.11 <= 1.11.0rc1
* 1.10 <= 1.10.2
* 1.9 <= 1.9.4
* 1.8 any version (if $wgEnableAPI has been switched on)

Solution:
Update to version 1.11.1, 1.10.3, or 1.9.5.
Comment 1 Lars Hartmann 2008-01-27 21:43:32 UTC
maintainers - please provide an updated ebuild
Comment 2 Philippe Trottier (RETIRED) gentoo-dev 2008-02-01 16:57:56 UTC
I will provide it as soon as I can, I am currently rebuilding my home system and don't have the ressource to make it right now. I hope Ill be able to sort this out by Monday.
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2008-02-06 10:15:42 UTC
Cleaned-up 1.1.11 ebuild commited to webapps overlay [1], fixed postinstall instructions etc. I didn't bump other versions since I simply wish all the legacy bloat would go to /dev/null. We really don't need 5 different branches of this in the tree.

[1] http://overlays.gentoo.org/svn/proj/webapps/migration/www-apps/mediawiki/
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-10 14:30:53 UTC
Could we get a fixed version in the tree?
Comment 5 Gunnar Wrobel (RETIRED) gentoo-dev 2008-02-15 11:06:07 UTC
I agree with Jakub on the other branches. I reduced the packge to the highest stable version and the newer mediawiki-1.11.1. 

Target archs:

 amd64 ppc sparc x86

I'll remove mediawiki-1.8.5 once mediawiki-1.11.1 is stable on the archs mentioned above.
Comment 6 Philippe Trottier (RETIRED) gentoo-dev 2008-02-15 12:39:10 UTC
Sorry, to say my system is still down, I got 2 broken processors back to back.

The only important version is 1.6.x as it can be used with older php versions, but I do think it is time for that one to die. It was my plan to kill all 1.7 1.8 1.9 1.10 as soon as this new system start working for more than 10 minutes at a time.

Thank you for doing the job this time.
Comment 7 Markus Meier gentoo-dev 2008-02-16 09:02:11 UTC
x86 stable and added RESTRICT="test" as they don't work (with jakubs permission).
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-16 12:18:06 UTC
Rerating as B since we're marking stable.
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2008-02-19 17:16:27 UTC
ppc stable
Comment 10 Raúl Porcel (RETIRED) gentoo-dev 2008-02-24 14:40:20 UTC
sparc stable
Comment 11 Steve Dibb (RETIRED) gentoo-dev 2008-02-25 15:09:33 UTC
amd64 stable
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-25 20:03:57 UTC
This one is ready for GLSA vote. I tend to vote NO.
Comment 13 Peter Volkov (RETIRED) gentoo-dev 2008-02-25 20:58:34 UTC
This bug was fixed in release snapshot.
Comment 14 Robert Buchholz (RETIRED) gentoo-dev 2008-02-25 22:11:16 UTC
NO, and closed.