Debian Security Advisory
DSA-3100-1 mediawiki -- security update
- Date Reported:
- 12 Dec 2014
- Affected Packages:
- mediawiki
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 772764.
In Mitre's CVE dictionary: CVE-2014-9277. - More information:
-
A flaw was discovered in mediawiki, a wiki engine: cross-domain-policy mangling allows an article editor to inject code into API consumers that deserialize PHP representations of the page from the API.
For the stable distribution (wheezy), this problem has been fixed in version 1:1.19.20+dfsg-0+deb7u2.
We recommend that you upgrade your mediawiki packages.