Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 89949 - www-apps/mediawiki: Unspecified Cross-Site Scripting Vulnerability
Summary: www-apps/mediawiki: Unspecified Cross-Site Scripting Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/14993/
Whiteboard: C4 [noglsa] jaervosz
Keywords:
: 86470 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-04-21 11:37 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-04-25 12:25 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-04-21 11:37:24 UTC
Description:
A vulnerability has been reported in MediaWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.

Certain unspecified input isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.

Successful exploitation requires that MediaWiki has been configured to output through HTML Tidy.

Solution:
Update to version 1.3.12 or 1.4.2.
http://sourceforge.net/project/showfiles.php?group_id=34373
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-21 22:32:41 UTC
web-apps please bump.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-21 22:33:06 UTC
*** Bug 86470 has been marked as a duplicate of this bug. ***
Comment 3 Aaron Walker (RETIRED) gentoo-dev 2005-04-22 05:45:24 UTC
Pls look at the metadata.xml.
Comment 4 Christian Parpart (RETIRED) gentoo-dev 2005-04-22 05:51:30 UTC
I'm on it, gimme some time (same for 1.4.2) this weekend, please
Comment 5 Christian Parpart (RETIRED) gentoo-dev 2005-04-25 02:13:51 UTC
all in the trees.
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-04-25 02:36:30 UTC
trapni: Please do not close security bugs until we stable-d and glsa-ed them :)

x86, amd64: please test and mark stable mediawiki
Comment 7 Simon Stelling (RETIRED) gentoo-dev 2005-04-25 04:10:36 UTC
1.3.12 is already stable: KEYWORDS="x86 amd64"

i'm unsure about 1.4.12, should we mark it stable too? previous 1.4.x seem all to be ~arch
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2005-04-25 04:26:07 UTC
blubb: you're right, no more stabling needed, it's ready for GLSA voting :)
Comment 9 Christian Parpart (RETIRED) gentoo-dev 2005-04-25 07:49:44 UTC
I'm using 1.4.x since beta on my gentoo systems, and now 1.4.2.
all archs are x86 and my desktop is amd64, though, I can confirm, that I didn't get any oddy results yet.

not marking fixed? hmm... sorry for that, I'll remember that for the next time :)
Comment 10 Thierry Carrez (RETIRED) gentoo-dev 2005-04-25 08:46:59 UTC
"Successful exploitation requires that MediaWiki has been configured to output through HTML Tidy" --> I suppose it's not the default --> C4? (specific config needed) --> I vote NO
Comment 11 Matthias Geerdsen (RETIRED) gentoo-dev 2005-04-25 09:37:44 UTC
from the release notes:

== MediaWiki 1.4.2 ==

(released 2005-04-20)

MediaWiki 1.4.2 is a security and bug fix release for the 1.4 stable release
series.

A cross-site scripting injection vulnerability was discovered, which
affects only MSIE clients and is only open if MediaWiki has been
manually configured to run output through HTML Tidy ($wgUseTidy).

Several other bugs are fixed in this release, see the changelog below.

_____

voting NO therefor
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-25 12:25:18 UTC
Two NO votes -> Closing.