[GLSA-201310-21] MediaWiki: Multiple vulnerabilities
Multiple vulnerabilities have been found in MediaWiki, the worst of which could lead to Denial of Service.
Background
The MediaWiki wiki web application as used on wikipedia.org.
Description
Multiple vulnerabilities have been discovered in MediaWiki. Please
review the CVE identifiers referenced below for details.
Impact
A remote attacker may be able to execute arbitrary code, perform
man-in-the-middle attacks, obtain sensitive information or perform
cross-site scripting attacks.
Workaround
There is no known workaround at this time.
Resolution
All MediaWiki 1.21.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.21.2"
All MediaWiki 1.20.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.20.7"
All MediaWiki 1.19.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.19.8"
Package | Affected Version |
---|---|
pkg:ebuild/www-apps/mediawiki?distro=gentoo | < 1.21.2 |
Package | Unaffected Version |
---|---|
pkg:ebuild/www-apps/mediawiki?distro=gentoo | >= 1.21.2 |
pkg:ebuild/www-apps/mediawiki?distro=gentoo | >= 1.20.7 |
pkg:ebuild/www-apps/mediawiki?distro=gentoo | >= 1.19.8 |
- ID
- GLSA-201310-21
- Severity
- normal
- URL
- https://security.gentoo.org/glsa/201310-21
- Published
-
2013-10-28T00:00:00
(11 years ago) - Modified
-
2013-10-28T00:00:00
(11 years ago) - Rights
- Gentoo Foundation, Inc.
- Other Advisories
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:ebuild/www-apps/mediawiki?distro=gentoo | www-apps | mediawiki | < 1.21.2 | gentoo | ||
Unaffected | pkg:ebuild/www-apps/mediawiki?distro=gentoo | www-apps | mediawiki | >= 1.21.2 | gentoo | ||
Unaffected | pkg:ebuild/www-apps/mediawiki?distro=gentoo | www-apps | mediawiki | >= 1.20.7 | gentoo | ||
Unaffected | pkg:ebuild/www-apps/mediawiki?distro=gentoo | www-apps | mediawiki | >= 1.19.8 | gentoo |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |