REDHAT-BUG-758171: Low severity Wikimedia MediaWiki vulnerability
An information disclosure flaw was found in the way MediaWiki, the wiki engine, processed 'curid' and 'oldid' request paramaters. A remote attacker could use this flaw to enumerate page titles on private MediaWiki installations.
Upstream bug report: [1] https://bugzilla.wikimedia.org/showbug.cgi?id=32276
An information disclosure flaw was found in the way MediaWiki, the wiki engine, performed action=ajax requests dispatching to relevant internal functions. These requests were dispatched without any read permissions checks being done. A remote attacker could use this flaw to obtain data on private MediaWiki installations.
Upstream bug report: [2] https://bugzilla.wikimedia.org/showbug.cgi?id=32616
References: [3] http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html [4] http://www.openwall.com/lists/oss-security/2011/11/29/6 [5] https://bugs.gentoo.org/showbug.cgi?id=392383
Upstream patch (covering both of the issues): [6] http://www.mediawiki.org/wiki/Special:Code/MediaWiki/104506
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-758171?
REDHAT-BUG-758171 is classified as an information disclosure vulnerability that allows enumeration of page titles.
How do I fix REDHAT-BUG-758171?
To fix REDHAT-BUG-758171, update your MediaWiki installation to the latest version that addresses this vulnerability.
Who is affected by REDHAT-BUG-758171?
REDHAT-BUG-758171 affects private MediaWiki installations using vulnerable versions of the MediaWiki software.
Can REDHAT-BUG-758171 be exploited remotely?
Yes, a remote attacker can exploit REDHAT-BUG-758171 to enumerate page titles on affected MediaWiki installations.
What are the request parameters involved in REDHAT-BUG-758171?
The request parameters involved in REDHAT-BUG-758171 are 'curid' and 'oldid'.