DSA-3046 mediawiki - security update
|
Información sobre el sistema
|
|
|
Software afectado |
Debian |
Descripción
|
It was reported that MediaWiki, a website engine for collaborative work,allowed to load user-created CSS on pages where user-created JavaScriptis not allowed. A wiki user could be tricked into performing actions bymanipulating the interface from CSS, or JavaScript code being executedfrom CSS, on security-wise sensitive pages like Special:Preferences andSpecial:UserLogin. This update removes the separation of CSS andJavaScript module allowance.
More info:
https://www.debian.org/security/2014/dsa-3046 |
Identificadores estándar
|
Propiedad |
Valor |
CVE |
CVE-2014-7295 and DSA-3046. |