[GLSA-201310-21] MediaWiki: Multiple vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 3
CVEs 15

Multiple vulnerabilities have been found in MediaWiki, the worst of which could lead to Denial of Service.

Background
The MediaWiki wiki web application as used on wikipedia.org.

Description
Multiple vulnerabilities have been discovered in MediaWiki. Please
review the CVE identifiers referenced below for details.

Impact
A remote attacker may be able to execute arbitrary code, perform
man-in-the-middle attacks, obtain sensitive information or perform
cross-site scripting attacks.

Workaround
There is no known workaround at this time.

Resolution
All MediaWiki 1.21.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.21.2"

All MediaWiki 1.20.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.20.7"

All MediaWiki 1.19.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.19.8"

Package Affected Version
pkg:ebuild/www-apps/mediawiki?distro=gentoo < 1.21.2
ID
GLSA-201310-21
Severity
normal
URL
https://security.gentoo.org/glsa/201310-21
Published
2013-10-28T00:00:00
(11 years ago)
Modified
2013-10-28T00:00:00
(11 years ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2013-1816 CVE-2013-1816 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1816
CVE CVE-2013-1817 CVE-2013-1817 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1817
CVE CVE-2013-1818 CVE-2013-1818 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1818
CVE CVE-2013-1951 CVE-2013-1951 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1951
CVE CVE-2013-2031 CVE-2013-2031 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2031
CVE CVE-2013-2032 CVE-2013-2032 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2032
CVE CVE-2013-2114 CVE-2013-2114 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2114
CVE CVE-2013-4301 CVE-2013-4301 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4301
CVE CVE-2013-4302 CVE-2013-4302 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4302
CVE CVE-2013-4303 CVE-2013-4303 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4303
CVE CVE-2013-4304 CVE-2013-4304 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4304
CVE CVE-2013-4305 CVE-2013-4305 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4305
CVE CVE-2013-4306 CVE-2013-4306 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4306
CVE CVE-2013-4307 CVE-2013-4307 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4307
CVE CVE-2013-4308 CVE-2013-4308 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4308
Bugzilla 460352 Bugzilla #460352 https://bugs.gentoo.org/show_bug.cgi?id=460352
Bugzilla 466124 Bugzilla #466124 https://bugs.gentoo.org/show_bug.cgi?id=466124
Bugzilla 468110 Bugzilla #468110 https://bugs.gentoo.org/show_bug.cgi?id=468110
Bugzilla 471140 Bugzilla #471140 https://bugs.gentoo.org/show_bug.cgi?id=471140
Bugzilla 483594 Bugzilla #483594 https://bugs.gentoo.org/show_bug.cgi?id=483594
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/www-apps/mediawiki?distro=gentoo www-apps mediawiki < 1.21.2 gentoo
Unaffected pkg:ebuild/www-apps/mediawiki?distro=gentoo www-apps mediawiki >= 1.21.2 gentoo
Unaffected pkg:ebuild/www-apps/mediawiki?distro=gentoo www-apps mediawiki >= 1.20.7 gentoo
Unaffected pkg:ebuild/www-apps/mediawiki?distro=gentoo www-apps mediawiki >= 1.19.8 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...