First published: Tue Nov 29 2011(Updated: )
An information disclosure flaw was found in the way MediaWiki, the wiki engine, processed 'curid' and 'oldid' request paramaters. A remote attacker could use this flaw to enumerate page titles on private MediaWiki installations. Upstream bug report: [1] <a href="https://bugzilla.wikimedia.org/show_bug.cgi?id=32276">https://bugzilla.wikimedia.org/show_bug.cgi?id=32276</a> An information disclosure flaw was found in the way MediaWiki, the wiki engine, performed action=ajax requests dispatching to relevant internal functions. These requests were dispatched without any read permissions checks being done. A remote attacker could use this flaw to obtain data on private MediaWiki installations. Upstream bug report: [2] <a href="https://bugzilla.wikimedia.org/show_bug.cgi?id=32616">https://bugzilla.wikimedia.org/show_bug.cgi?id=32616</a> References: [3] <a href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html">http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html</a> [4] <a href="http://www.openwall.com/lists/oss-security/2011/11/29/6">http://www.openwall.com/lists/oss-security/2011/11/29/6</a> [5] <a href="https://bugs.gentoo.org/show_bug.cgi?id=392383">https://bugs.gentoo.org/show_bug.cgi?id=392383</a> Upstream patch (covering both of the issues): [6] <a href="http://www.mediawiki.org/wiki/Special:Code/MediaWiki/104506">http://www.mediawiki.org/wiki/Special:Code/MediaWiki/104506</a>
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-758171 is classified as an information disclosure vulnerability that allows enumeration of page titles.
To fix REDHAT-BUG-758171, update your MediaWiki installation to the latest version that addresses this vulnerability.
REDHAT-BUG-758171 affects private MediaWiki installations using vulnerable versions of the MediaWiki software.
Yes, a remote attacker can exploit REDHAT-BUG-758171 to enumerate page titles on affected MediaWiki installations.
The request parameters involved in REDHAT-BUG-758171 are 'curid' and 'oldid'.