REDHAT-BUG-571926: Medium severity Wikimedia MediaWiki vulnerability
MediaWiki upstream has released new v1.15.2 version: http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html
of MediaWiki fixing two security issues (from upstream announcement):
a, "A CSS validation issue was discovered which allows editors to display external images in wiki pages. This is a privacy concern on public wikis, since a malicious user may link to an image on a server they control, which would allow that attacker to gather IP addresses and other information from users of the public wiki. All sites running publicly-editable MediaWiki installations are advised to upgrade. All versions of MediaWiki (prior to this one) are affected."
CVE identifier of CVE-2010-1189 has been assigned to this.
--
b, "A data leakage vulnerability was discovered in thumb.php which affects wikis which restrict access to private files using imgauth.php, or some similar scheme. All versions of MediaWiki since 1.5 are affected.
Deleting thumb.php is a suitable workaround for private wikis which do not use $wgThumbnailScriptPath or $wgLocalRepo['thumbScriptUrl']."
CVE identifier of CVE-2010-1190 has been assigned to this.
Upstream patch: http://download.wikimedia.org/mediawiki/1.15/mediawiki-1.15.2.patch.gz
References: http://secunia.com/advisories/38856/
CVE Request: http://www.openwall.com/lists/oss-security/2010/03/09/4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-571926?
REDHAT-BUG-571926 addresses multiple vulnerabilities that could allow for remote code execution or data leakage.
How do I fix REDHAT-BUG-571926?
To fix REDHAT-BUG-571926, you should upgrade to MediaWiki version 1.15.2 or later.
What vulnerabilities does REDHAT-BUG-571926 patch?
REDHAT-BUG-571926 patches two security vulnerabilities in MediaWiki, specifically CVE-2010-1189 and CVE-2010-1190.
Which versions of MediaWiki are affected by REDHAT-BUG-571926?
MediaWiki versions prior to 1.15.2 are affected by REDHAT-BUG-571926.
Is there a workaround for REDHAT-BUG-571926?
There are no specific workarounds for REDHAT-BUG-571926; upgrading to the latest version is recommended.