Advisories ยป MGASA-2014-0400

Updated mediawiki packages fix security vulnerbilities

Publication date: 07 Oct 2014
Modification date: 07 Oct 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-7199 , CVE-2014-7295

Description

Updated mediawiki packages fix security vulnerability:

MediaWiki before 1.23.4 is vulnerable to cross-site scripting due to
JavaScript injection via CSS in uploaded SVG files (CVE-2014-7199).

MediaWiki before 1.23.5 is vulnerable to cross-site scripting due to
JavaScript injection via user-specificed CSS in certain special pages
(CVE-2014-7295).
                

References

SRPMS

3/core

4/core