[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3671-1] mediawiki security update

Debian LTS Advisory DLA-3671-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                       Guilhem Moulin
November 28, 2023                             https://wiki.debian.org/LTS

Package        : mediawiki
Version        : 1:1.31.16-1+deb10u7
CVE ID         : CVE-2023-3550 CVE-2023-45362 CVE-2023-45363

Multiple vulnerabilities were found in mediawiki, a website engine for
collaborative work, that could lead to information disclosure, privilege
escalation, or denial of service.


    Carlos Bello reported a stored cross-site scripting (XSS)
    vulnerability when uploading crafted XML file to Special:Upload,
    which can lead to privilege escalation.  (However .xml file uploads
    are not allowed in the default configuration.)


    Tobias Frei discovered that diff-multi-sameuser (“X intermediate
    revisions by the same user not shown”) ignores username suppression,
    which can lead to information leak.


    It was discovered that querying pages redirected to other variants
    with `redirects` and `converttitles` parameters set would cause
    a denial of service (unbounded loop and RequestTimeoutException).

For Debian 10 buster, these problems have been fixed in version

We recommend that you upgrade your mediawiki packages.

For the detailed security status of mediawiki please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply to: