Advisories ยป MGASA-2018-0433

Updated mediawiki packages fix security vulnerabilities

Publication date: 03 Nov 2018
Modification date: 03 Nov 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-0503 , CVE-2018-0504 , CVE-2018-0505

Description

Updated mediawiki packages fix security vulnerabilities:

'$wgRateLimits' entry for 'user' overrides 'newbie' (CVE-2018-0503).

When a log event is (partially) hidden Special:Redirect/logid can link
to the incorrect log and reveal hidden information (CVE-2018-0504).

BotPasswords can bypass CentralAuth's account lock (CVE-2018-0505).
                

References

SRPMS

6/core