Debian Security Advisory
DSA-3036-1 mediawiki -- security update
- Date Reported:
- 26 Sep 2014
- Affected Packages:
- mediawiki
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 762754.
In Mitre's CVE dictionary: CVE-2014-7199. - More information:
-
It was discovered that MediaWiki, a wiki engine, did not sufficiently filter CSS in uploaded SVG files, allowing for cross site scripting.
For the stable distribution (wheezy), this problem has been fixed in version 1:1.19.19+dfsg-0+deb7u1.
For the unstable distribution (sid), this problem has been fixed in version 1:1.19.19+dfsg-1.
We recommend that you upgrade your mediawiki packages.