Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 116495 - www-apps/mediawiki: 1.5.4 includes security fixes
Summary: www-apps/mediawiki: 1.5.4 includes security fixes
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://sourceforge.net/project/showno...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-23 07:39 UTC by Stefan Cornelius (RETIRED)
Modified: 2005-12-23 09:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Cornelius (RETIRED) gentoo-dev 2005-12-23 07:39:43 UTC
A hardcoded internal placeholder string has been replaced with a random
one. This closes a hole where security checks in inline style attributes
could be bypassed, injecting JavaScript code that could execute in
Microsoft Internet Explorer.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2005-12-23 07:42:22 UTC
maintainers are already working on ebuilds. Anybody knows if 1.4.X is also affected?
Comment 2 Stefan Cornelius (RETIRED) gentoo-dev 2005-12-23 09:41:15 UTC
new ebuild in portage, 1.4.x seems unaffected and we can close without a glsa.