mediawiki: CVE-2014-9475: thumb.php outputs wikitext message as raw HTML

Related Vulnerabilities: CVE-2014-9475  

Debian Bug report logs - #773654
mediawiki: CVE-2014-9475: thumb.php outputs wikitext message as raw HTML

version graph

Reported by: Sebastien Delafond <seb@debian.org>

Date: Sun, 21 Dec 2014 15:57:02 UTC

Severity: important

Tags: fixed-upstream, patch, security, upstream

Found in versions mediawiki/1:1.19.20+dfsg-2.1, mediawiki/1:1.19.5-1

Fixed in versions mediawiki/1:1.19.20+dfsg-0+deb7u3, mediawiki/1:1.19.20+dfsg-2.2

Done: thijs@kinkhorst.com (Thijs Kinkhorst)

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Mediawiki Maintenance Team <pkg-mediawiki-devel@lists.alioth.debian.org>:
Bug#773654; Package mediawiki. (Sun, 21 Dec 2014 15:57:06 GMT) (full text, mbox, link).


Acknowledgement sent to Sebastien Delafond <seb@debian.org>:
New Bug report received and forwarded. Copy sent to Mediawiki Maintenance Team <pkg-mediawiki-devel@lists.alioth.debian.org>. (Sun, 21 Dec 2014 15:57:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Sebastien Delafond <seb@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: mediawiki: Security issue: thumb.php outputs wikitext message as raw HTML
Date: Sun, 21 Dec 2014 16:55:29 +0100
Package: mediawiki
Version: 1:1.19.20+dfsg-2.1
Severity: important
Tags: upstream patch

>From upstream bug T76686 (still not public): thumb.php outputs
wikitext message as raw HTML, which could lead to xss. Permission to
edit MediaWiki namespace is required to exploit this.

The upstream patch fixing this is at
https://github.com/wikimedia/mediawiki/commit/fdd3f464ef9aa7f3276a2a8dddc85e3769cfda83,
and I have uploaded 1:1.19.20+dfsg-2.2 to DELAYED/2, that includes
it. The corresponding debdiff is included at the end of this email.

Cheers,

--Seb

-- System Information:
Debian Release: 7.7
  APT prefers stable
  APT policy: (501, 'stable'), (500, 'oldstable-proposed-updates'), (500, 'oldstable'), (1, 'unstable'), (1, 'testing')
Architecture: i386 (i686)

Kernel: Linux 3.2.0-4-686-pae (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



Information forwarded to debian-bugs-dist@lists.debian.org, Mediawiki Maintenance Team <pkg-mediawiki-devel@lists.alioth.debian.org>:
Bug#773654; Package mediawiki. (Sun, 21 Dec 2014 16:03:04 GMT) (full text, mbox, link).


Acknowledgement sent to Sébastien Delafond <seb@debian.org>:
Extra info received and forwarded to list. Copy sent to Mediawiki Maintenance Team <pkg-mediawiki-devel@lists.alioth.debian.org>. (Sun, 21 Dec 2014 16:03:04 GMT) (full text, mbox, link).


Message #10 received at 773654@bugs.debian.org (full text, mbox, reply):

From: Sébastien Delafond <seb@debian.org>
To: 773654@bugs.debian.org
Subject: Debdiff
Date: Sun, 21 Dec 2014 16:58:34 +0100
[Message part 1 (text/plain, inline)]
 
[mediawiki.debdiff (text/plain, attachment)]

Added tag(s) security. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 21 Dec 2014 21:33:16 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 21 Dec 2014 21:33:20 GMT) (full text, mbox, link).


Marked as fixed in versions mediawiki/1:1.19.20+dfsg-2.2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 23 Dec 2014 12:57:05 GMT) (full text, mbox, link).


Marked as found in versions mediawiki/1:1.19.5-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 23 Dec 2014 12:57:08 GMT) (full text, mbox, link).


Marked as fixed in versions mediawiki/1:1.19.20+dfsg-0+deb7u3. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 24 Dec 2014 06:33:04 GMT) (full text, mbox, link).


Changed Bug title to 'mediawiki: CVE-2014-9475: thumb.php outputs wikitext message as raw HTML' from 'mediawiki: Security issue: thumb.php outputs wikitext message as raw HTML' Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 04 Jan 2015 04:51:29 GMT) (full text, mbox, link).


Marked Bug as done Request was from thijs@kinkhorst.com (Thijs Kinkhorst) to control@bugs.debian.org. (Wed, 08 Apr 2015 13:06:22 GMT) (full text, mbox, link).


Notification sent to Sebastien Delafond <seb@debian.org>:
Bug acknowledged by developer. (Wed, 08 Apr 2015 13:06:23 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 07 May 2015 07:28:14 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 19:10:31 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.