Bug 1071139 (CVE-2014-2244)
Summary: | CVE-2014-2244 mediawiki: HTML injection | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Murray McAllister <mmcallis> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED RAWHIDE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | extras-orphan, gwync, ian, mike, puiterwijk |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | mediawiki 1.22.3, mediawiki 1.21.6, mediawiki 1.19.13 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-12-14 16:41:09 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1071142, 1071143, 1071157 | ||
Bug Blocks: |
Description
Murray McAllister
2014-02-28 07:01:34 UTC
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 1071142] Created mediawiki119 tracking bugs for this issue: Affects: epel-6 [bug 1071143] Created mediawiki tracking bugs for this issue: Affects: epel-5 [bug 1071157] MITRE assigned CVE-2014-2244 to this issue: http://www.openwall.com/lists/oss-security/2014/03/01/2 mediawiki-1.21.6-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. mediawiki-1.21.6-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. For the 1.19 branch, this was not properly fixed in 1.19.12 even though it was noted as having been fixed there. It was actually fixed in 1.19.13 properly. http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000142.html This probably will get another CVE assigned by MITRE. mediawiki119-1.19.13-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report. |