Boletines de Vulnerabilidades

DSA-3046 mediawiki - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

It was reported that MediaWiki, a website engine for collaborative work,allowed to load user-created CSS on pages where user-created JavaScriptis not allowed. A wiki user could be tricked into performing actions bymanipulating the interface from CSS, or JavaScript code being executedfrom CSS, on security-wise sensitive pages like Special:Preferences andSpecial:UserLogin. This update removes the separation of CSS andJavaScript module allowance.

More info:

https://www.debian.org/security/2014/dsa-3046

Identificadores estándar

Propiedad Valor
CVE CVE-2014-7295 and DSA-3046.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-10-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT