Debian Security Advisory
DSA-2957-1 mediawiki -- security update
- Date Reported:
- 12 Jun 2014
- Affected Packages:
- mediawiki
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-3966.
- More information:
-
Omer Iqbal discovered that Mediawiki, a wiki engine, parses invalid usernames on Special:PasswordReset as wikitext when $wgRawHtml is enabled. On such wikis this allows an unauthenticated attacker to insert malicious JavaScript, a cross site scripting attack.
For the stable distribution (wheezy), this problem has been fixed in version 1:1.19.16+dfsg-0+deb7u1.
For the unstable distribution (sid), this problem has been fixed in version 1:1.19.16+dfsg-1.
We recommend that you upgrade your mediawiki packages.