aboutsummaryrefslogtreecommitdiffstats
path: root/english/lts
diff options
context:
space:
mode:
authorGuilhem Moulin <guilhem@debian.org>2023-11-28 12:48:47 +0100
committerGuilhem Moulin <guilhem@debian.org>2023-11-28 12:48:47 +0100
commit0bb60b448da8c2c34b995634ff6410ffcbd51c0b (patch)
tree5122fdeecbd04e53149d17ca914034a5f27020f2 /english/lts
parent284726b9788e391735dfbcee3ceca3d5cfdb2100 (diff)
DLA-3671-1 for mediawiki
Diffstat (limited to 'english/lts')
-rw-r--r--english/lts/security/2023/dla-3671.data10
-rw-r--r--english/lts/security/2023/dla-3671.wml46
2 files changed, 56 insertions, 0 deletions
diff --git a/english/lts/security/2023/dla-3671.data b/english/lts/security/2023/dla-3671.data
new file mode 100644
index 00000000000..4de20941baa
--- /dev/null
+++ b/english/lts/security/2023/dla-3671.data
@@ -0,0 +1,10 @@
+<define-tag pagetitle>DLA-3671-1 mediawiki</define-tag>
+<define-tag report_date>2023-11-28</define-tag>
+<define-tag secrefs>CVE-2023-3550 CVE-2023-45362 CVE-2023-45363</define-tag>
+<define-tag packages>mediawiki</define-tag>
+<define-tag isvulnerable>yes</define-tag>
+<define-tag fixed>yes</define-tag>
+<define-tag fixed-section>no</define-tag>
+
+#use wml::debian::security
+
diff --git a/english/lts/security/2023/dla-3671.wml b/english/lts/security/2023/dla-3671.wml
new file mode 100644
index 00000000000..5af02ba8ea1
--- /dev/null
+++ b/english/lts/security/2023/dla-3671.wml
@@ -0,0 +1,46 @@
+<define-tag description>LTS security update</define-tag>
+<define-tag moreinfo>
+<p>Multiple vulnerabilities were found in mediawiki, a website engine for
+collaborative work, that could lead to information disclosure, privilege
+escalation, or denial of service.</p>
+
+<ul>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2023-3550">CVE-2023-3550</a>
+
+ <p>Carlos Bello reported a stored cross-site scripting (XSS)
+ vulnerability when uploading crafted XML file to <code>Special:Upload</code>,
+ which can lead to privilege escalation. (However <code>.xml</code> file uploads
+ are not allowed in the default configuration.)</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2023-45362">CVE-2023-45362</a>
+
+ <p>Tobias Frei discovered that diff-multi-sameuser (“X intermediate
+ revisions by the same user not shown”) ignores username suppression,
+ which can lead to information leak.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2023-45363">CVE-2023-45363</a>
+
+ <p>It was discovered that querying pages redirected to other variants
+ with <code>redirects</code> and <code>converttitles</code> parameters set would cause
+ a denial of service (unbounded loop and <code>RequestTimeoutException</code>).</p></li>
+
+</ul>
+
+<p>For Debian 10 buster, these problems have been fixed in version
+1:1.31.16-1+deb10u7.</p>
+
+<p>We recommend that you upgrade your mediawiki packages.</p>
+
+<p>For the detailed security status of mediawiki please refer to
+its security tracker page at:
+<a href="https://security-tracker.debian.org/tracker/mediawiki">https://security-tracker.debian.org/tracker/mediawiki</a></p>
+
+<p>Further information about Debian LTS security advisories, how to apply
+these updates to your system and frequently asked questions can be
+found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p>
+</define-tag>
+
+# do not modify the following line
+#include "$(ENGLISHDIR)/lts/security/2023/dla-3671.data"
+# $Id: $

© 2014-2024 Faster IT GmbH | imprint | privacy policy