First published: Fri Apr 13 2018(Updated: )
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.35.13-1+deb11u2 1:1.39.7-1~deb12u1 1:1.39.8-1 | |
Wikimedia MediaWiki | >=1.27.0<1.27.2 | |
Wikimedia MediaWiki | >=1.28.0<1.28.1 | |
Debian GNU/Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0367 is classified as having a moderate severity due to its impact on security related to file accessibility.
To remediate CVE-2017-0367, upgrade MediaWiki to version 1.28.1, 1.27.2, or later where the issue has been addressed.
CVE-2017-0367 affects MediaWiki versions prior to 1.28.1 and 1.27.2.
CVE-2017-0367 involves an insecure use of the temporary directory that could lead to local file exposure.
Yes, this vulnerability can also affect Debian Linux 7.0 when using impacted versions of MediaWiki.