Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 114581

Summary: www-apps/mediawiki <= 1.5.2: Remote code execution
Product: Gentoo Security Reporter: Max Lorenz <meax>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: carlo, web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
URL: http://sourceforge.net/project/shownotes.php?group_id=34373&release_id=375755
Whiteboard: ~1 [noglsa] jaervosz
Package list:
Runtime testing required: ---

Description Max Lorenz 2005-12-05 16:56:53 UTC
NOTE: this only affects versions >=1.5.0 which are currently in ~arch.

mediawiki-1.5.3 has been released on December 4th with a security fix:
"Validation of the user language option was broken by a code change in
May 2005, opening the possibility of remote code execution as this
parameter is used in forming a class name dynamically created with
eval()."

Thanks, Max
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 22:11:27 UTC
Web-apps please bump. 
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 23:25:55 UTC
*** Bug 114582 has been marked as a duplicate of this bug. ***
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 23:26:14 UTC
Fixed with comment on bug #114582