Debian Security Advisory

DSA-3100-1 mediawiki -- security update

Date Reported:
12 Dec 2014
Affected Packages:
mediawiki
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 772764.
In Mitre's CVE dictionary: CVE-2014-9277.
More information:

A flaw was discovered in mediawiki, a wiki engine: cross-domain-policy mangling allows an article editor to inject code into API consumers that deserialize PHP representations of the page from the API.

For the stable distribution (wheezy), this problem has been fixed in version 1:1.19.20+dfsg-0+deb7u2.

We recommend that you upgrade your mediawiki packages.