Updated mediawiki packages fix security vulnerabilities
Publication date: 02 Nov 2015Modification date: 02 Nov 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-8001 , CVE-2015-8002 , CVE-2015-8003 , CVE-2015-8004 , CVE-2015-8005
Description
Updated mediawiki packages fix security vulnerabilities: In MediaWiki before 1.23.11, the API failed to correctly stop adding new chunks to the upload when the reported size was exceeded, allowing a malicious user to upload add an infinite number of chunks for a single file upload (CVE-2015-8001). In MediaWiki before 1.23.11, a malicious user could upload chunks of 1 byte for very large files, potentially creating a very large number of files on the server's filesystem (CVE-2015-8002). In MediaWiki before 1.23.11, it is not possible to throttle file uploads, or in other words, rate limit them (CVE-2015-8003). In MediaWiki before 1.23.11, a missing authorization check when removing suppression from a revision allowed users with the 'viewsuppressed' user right but not the appropriate 'suppressrevision' user right to unsuppress revisions (CVE-2015-8004). In MediaWiki before 1.23.11, thumbnails of PNG files generated with ImageMagick contained the local file path in the image (CVE-2015-8005).
References
- https://bugs.mageia.org/show_bug.cgi?id=16990
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html
- http://openwall.com/lists/oss-security/2015/10/29/14
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8001
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8002
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8003
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8004
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8005
SRPMS
5/core
- mediawiki-1.23.11-1.mga5