MediaWiki Page Template HTML Injection Vulnerability

Solution:
The vendor has addressed this issue in MediaWiki legacy version 1.3.13 and the stable series version 1.4.5.

Gentoo Linux has released advisory GLSA 200506-12 addressing this issue. Gentoo recommends all MediaWiki users should upgrade to the latest available versions:

# emerge --sync
# emerge --ask --oneshot --verbose www-apps/mediawiki

SUSE has released a security summary report (SUSE-SR:2005:019) addressing this and other issues. Please see the referenced advisory for further information.


MediaWiki MediaWiki-stable 20031117

MediaWiki MediaWiki-stable 20030829

MediaWiki MediaWiki-stable 20031107

MediaWiki MediaWiki 1.3

MediaWiki MediaWiki 1.3.1

MediaWiki MediaWiki 1.3.10

MediaWiki MediaWiki 1.3.11

MediaWiki MediaWiki 1.3.2

MediaWiki MediaWiki 1.3.3

MediaWiki MediaWiki 1.3.4

MediaWiki MediaWiki 1.3.5

MediaWiki MediaWiki 1.3.6

MediaWiki MediaWiki 1.3.7

MediaWiki MediaWiki 1.3.8

MediaWiki MediaWiki 1.3.9

MediaWiki MediaWiki 1.4 beta3

MediaWiki MediaWiki 1.4 beta2

MediaWiki MediaWiki 1.4 beta4

MediaWiki MediaWiki 1.4 beta1

MediaWiki MediaWiki 1.4 beta5

MediaWiki MediaWiki 1.4.1

MediaWiki MediaWiki 1.4.2

MediaWiki MediaWiki 1.4.3


 

Privacy Statement
Copyright 2010, SecurityFocus