Debian Security Advisory

DSA-3036-1 mediawiki -- security update

Date Reported:
26 Sep 2014
Affected Packages:
mediawiki
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 762754.
In Mitre's CVE dictionary: CVE-2014-7199.
More information:

It was discovered that MediaWiki, a wiki engine, did not sufficiently filter CSS in uploaded SVG files, allowing for cross site scripting.

For the stable distribution (wheezy), this problem has been fixed in version 1:1.19.19+dfsg-0+deb7u1.

For the unstable distribution (sid), this problem has been fixed in version 1:1.19.19+dfsg-1.

We recommend that you upgrade your mediawiki packages.