Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 491278 (CVE-2013-4567) - <www-apps/mediawiki-{1.19.9,1.20.8,1.21.3}: Multiple vulnerabilities (CVE-2013-{4567,4568,4569})
Summary: <www-apps/mediawiki-{1.19.9,1.20.8,1.21.3}: Multiple vulnerabilities (CVE-201...
Status: RESOLVED FIXED
Alias: CVE-2013-4567
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-14 22:11 UTC by Alex Xu (Hello71)
Modified: 2013-12-25 20:39 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Xu (Hello71) 2013-11-14 22:11:37 UTC
I would like to announce the release of MediaWiki 1.21.3, 1.20.8 and
1.19.9. These releases fix 2 security related bugs that could affect users
of MediaWiki. Download links are given at the end of this email.

* Kevin Israel (Wikipedia user PleaseStand) identified and reported two
vectors for injecting Javascript in CSS that bypassed MediaWiki's blacklist
(CVE-2013-4567, CVE-2013-4568).
<https://bugzilla.wikimedia.org/show_bug.cgi?id=55332>

* Internal review while debugging a site issue discovered that MediaWiki
and the CentralNotice extension were incorrectly setting cache headers when
a user was autocreated, causing the user's session cookies to be cached,
and returned to other users (CVE-2013-4572).
<https://bugzilla.wikimedia.org/show_bug.cgi?id=53032>


Additionally, the following extensions have been updated to fix security
issues:

* CleanChanges: MediaWiki steward Teles reported that revision-deleted IP's
are not correctly hidden when this extension is used (CVE-2013-4569).
<https://bugzilla.wikimedia.org/show_bug.cgi?id=54294>

* ZeroRatedMobileAccess: Tomasz Chlebowski reported an XSS vulnerability
(CVE-2013-4573).
<https://bugzilla.wikimedia.org/show_bug.cgi?id=55991>

* CentralAuth: MediaWiki developer Platonides reported a login CSRF in
CentralAuth (CVE-2012-5394).
<https://bugzilla.wikimedia.org/show_bug.cgi?id=40747>


Full release notes for 1.21.3:
<https://www.mediawiki.org/wiki/Release_notes/1.21>

Full release notes for 1.20.8:
<https://www.mediawiki.org/wiki/Release_notes/1.20>

Full release notes for 1.19.9:
<https://www.mediawiki.org/wiki/Release_notes/1.19>

For information about how to upgrade, see
<https://www.mediawiki.org/wiki/Manual:Upgrading>
Comment 1 Tim Harder gentoo-dev 2013-12-10 07:57:47 UTC
Arches, please stabilize:
=www-apps/mediawiki-1.19.9
=www-apps/mediawiki-1.20.8
=www-apps/mediawiki-1.21.3
Comment 2 Agostino Sarubbo gentoo-dev 2013-12-10 13:18:10 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-12-10 13:23:50 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-12-13 09:26:47 UTC
ppc stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 5 Yury German Gentoo Infrastructure gentoo-dev 2013-12-14 06:03:14 UTC
Maintainer(s), Thank you for cleanup!
Comment 6 Sergey Popov gentoo-dev 2013-12-15 09:59:20 UTC
Thanks for your work.

GLSA vote: no
Comment 7 Chris Reffett (RETIRED) gentoo-dev Security 2013-12-15 14:12:56 UTC
GLSA vote: no. Closing noglsa.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2013-12-25 20:39:08 UTC
CVE-2013-4569 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4569):
  The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before
  1.20.8, and 1.21.x before 1.21.3, when "Group changes by page in recent
  changes and watchlist" is enabled, allows remote attackers to obtain
  sensitive information (revision-deleted IPs) via the Recent Changes page.

CVE-2013-4568 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4568):
  Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki
  before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote
  attackers to conduct cross-site scripting (XSS) attacks via certain
  non-ASCII characters in CSS, as demonstrated using variations of
  "expression" containing (1) full width characters or (2) IPA extensions,
  which are converted and rendered by Internet Explorer.

CVE-2013-4567 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4567):
  Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki
  before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote
  attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace)
  character in CSS.