Bug 882325 (CVE-2012-5391)
Summary: | CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | axel.thimm, extras-orphan, herrold, ian, puiterwijk, smooge |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | MediaWiki 1.20.1, MediaWiki 1.19.3, MediaWiki 1.18.6 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-04-19 08:39:59 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 882344, 882345, 885014, 885016 | ||
Bug Blocks: |
Description
Jan Lieskovsky
2012-11-30 16:59:24 UTC
Relevant upstream patch: [3] https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=d834a4892af5ea57b3ee387dad79ad1a2205acad This issue affects the versions of the mediawiki package, as shipped with Fedora release of 16 and 17. -- This issue affects the version of the mediawiki package, as shipped with Fedora EPEL 5. For the remaining issues, that got fixed in MediaWiki 1.20.1, MediaWiki 1.19.3 and MediaWiki 1.18.6, exactly: * A similar vulnerability was also identified in the CentralAuth Extension, and assigned CVE-2012-5395. Upstream bug: https://bugzilla.wikimedia.org/show_bug.cgi?id=40962 * Wikipedia user PleaseStand discovered that a new API feature in MediaWiki 1.20 allowed for HTML code to be injected into the "editfont" option. Upstream bug: https://bugzilla.wikimedia.org/show_bug.cgi?id=42202 Upstream patches: https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=fe45ba87528d855b4f12785016280451bd7893cf https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=8e57acf21152a688dcb147e6e2bf5c97ef6860af * Wikipedia user PleaseStand discovered that a PCRE backtrack limit could easily be exceeded, causing recent changes and history pages to fail to display. Upstream bug: https://bugzilla.wikimedia.org/show_bug.cgi?id=41400 Upstream patch: https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=7f9fe1b29df6ecee9a9c90f6806d7bf8848ff0b1 None of these would affect / would be applicable to the code of the mediawiki packages, as shipped with Fedora release of 16, 17, and Fedora EPEL 5 (IOW these versions would NOT be vulnerable to above three security flaws). Created mediawiki tracking bugs for this issue Affects: fedora-all [bug 882344] Affects: epel-5 [bug 882345] I will apply the upstream patch to the Fedora and EPEL repos. Also impacted: mediawiki119 package for EPEL 6 (In reply to comment #6) > Also impacted: mediawiki119 package for EPEL 6 This is correct. Thank you for pointing out (mediawiki116 should be included in the list too). Will do shortly. Created mediawiki116 tracking bugs for this issue Affects: epel-all [bug 885016] mediawiki-1.19.4-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report. mediawiki-1.19.4-2.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report. As noted in the mediawiki119 tracking bug, this has also been fixed for that one as well. The EPEL5 version is the only one not yet closed, because that branch is orphaned. |