Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 145612 - www-apps/mediawiki 1.6.8 * Fixed potential XSS in profileinfo.php
Summary: www-apps/mediawiki 1.6.8 * Fixed potential XSS in profileinfo.php
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [?] Falco
Keywords:
: 145613 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-08-30 08:34 UTC by Philippe Trottier (RETIRED)
Modified: 2006-10-03 07:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Philippe Trottier (RETIRED) gentoo-dev 2006-08-30 08:34:58 UTC
I have been cleaning a lot of mediawiki stuff today and I read this ... the ebuild is already online. fixing this problem:

http://mail.wikipedia.org/pipermail/mediawiki-announce/2006-July/000050.html

Do what you want, It's fixed, it is more to advertise to people who installed the 1.6.x series and would not know about it.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-30 09:00:59 UTC
web-apps please advise.
Comment 2 Philippe Trottier (RETIRED) gentoo-dev 2006-08-30 09:09:31 UTC
145613 is a duplicate of this close the one that is not making sense. the secure or the non secure. My appoligy for creating 2 bugs.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-30 09:52:05 UTC
*** Bug 145613 has been marked as a duplicate of this bug. ***
Comment 4 Philippe Trottier (RETIRED) gentoo-dev 2006-08-31 02:01:25 UTC
It seems this vulnerability is probably not relevent on the default way gentoo compiles php. I'd like others to confirm that as I am not a php guru.
Comment 5 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-09-08 05:35:16 UTC
"Only versions and configurations of PHP vulnerable to the
$GLOBALS overwrite vulnerability are affected."

our default configuration is safe.

Thus, this should be fixed but with no glsa, and this is really not critical.

I don't know if the 1.5 branch is affected. Our latest stable version is 1.5.8. web-apps, please could you check this, thanks.
Comment 6 Philippe Trottier (RETIRED) gentoo-dev 2006-09-08 06:26:50 UTC
1.5.8 should not be affected by this problem as per the mediawiki webpage. 
1.6.8 is already released as testing (before even this bug was filed)
All vulnerable versions have been removed from the tree

Let's close this bug and call it a day, unless someone can say 1.5.8 is vulnerable.
Comment 7 Philippe Trottier (RETIRED) gentoo-dev 2006-10-03 07:18:41 UTC
OK guys can we close this ? 1.6.8 is now stable, php5 of gentoo is not affected.. let's close this.
Comment 8 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-03 07:49:51 UTC
closing without GLSA since the affected packages were all marked unstable at that time, correct me if I am wrong there