Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 114581 - www-apps/mediawiki <= 1.5.2: Remote code execution
Summary: www-apps/mediawiki <= 1.5.2: Remote code execution
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High trivial (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/project/showno...
Whiteboard: ~1 [noglsa] jaervosz
Keywords:
: 114582 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-12-05 16:56 UTC by Max Lorenz
Modified: 2005-12-05 23:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Max Lorenz 2005-12-05 16:56:53 UTC
NOTE: this only affects versions >=1.5.0 which are currently in ~arch.

mediawiki-1.5.3 has been released on December 4th with a security fix:
"Validation of the user language option was broken by a code change in
May 2005, opening the possibility of remote code execution as this
parameter is used in forming a class name dynamically created with
eval()."

Thanks, Max
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 22:11:27 UTC
Web-apps please bump. 
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 23:25:55 UTC
*** Bug 114582 has been marked as a duplicate of this bug. ***
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-12-05 23:26:14 UTC
Fixed with comment on bug #114582