{"id":"MGASA-2015-0142","summary":"Updated mediawiki packages fix security vulnerabilities","details":"Updated mediawiki packages fix security vulnerabilities:\n\nIn MediaWiki before 1.23.9, one could circumvent the SVG MIME blacklist for\nembedded resources. This allowed an attacker to embed JavaScript in the SVG\n(CVE-2015-2931).\n\nIn MediaWiki before 1.23.9, the SVG filter to prevent injecting JavaScript\nusing animate elements was incorrect (CVE-2015-2932).\n\nIn MediaWiki before 1.23.9, a stored XSS vulnerability exists due to the way\nattributes were expanded in MediaWiki's Html class, in combination with\nLanguageConverter substitutions (CVE-2015-2933).\n\nIn MediaWiki before 1.23.9, MediaWiki's SVG filtering could be bypassed with\nentity encoding under the Zend interpreter. This could be used to inject\nJavaScript (CVE-2015-2934).\n\nIn MediaWiki before 1.23.9, one could bypass the style filtering for SVG\nfiles to load external resources. This could violate the anonymity of users\nviewing the SVG (CVE-2015-2935).\n\nIn MediaWiki before 1.23.9, MediaWiki versions using PBKDF2 for password\nhashing (not the default for 1.23) are vulnerable to DoS attacks using\nextremely long passwords (CVE-2015-2936).\n\nIn MediaWiki before 1.23.9, MediaWiki is vulnerable to \"Quadratic Blowup\"\nDoS attacks, under both HHVM and Zend PHP (CVE-2015-2937).\n\nIn MediaWiki before 1.23.9, the MediaWiki feature allowing a user to preview\nanother user's custom JavaScript could be abused for privilege escalation\n(CVE-2015-2938).\n\nIn MediaWiki before 1.23.9, function names were not sanitized in Lua error\nbacktraces, which could lead to XSS (CVE-2015-2939).\n\nIn MediaWiki before 1.23.9, the CheckUser extension did not prevent CSRF\nattacks on the form allowing checkusers to look up sensitive information\nabout other users. Since the use of CheckUser is logged, the CSRF could be\nabused to defame a trusted user or flood the logs with noise (CVE-2015-2940).\n\nThe mediawiki package has been updated to version 1.23.9, fixing these issues\nand other bugs.\n","modified":"2026-04-16T06:23:22.310433469Z","published":"2015-04-09T22:44:14Z","upstream":["CVE-2015-2931","CVE-2015-2932","CVE-2015-2933","CVE-2015-2934","CVE-2015-2935","CVE-2015-2936","CVE-2015-2937","CVE-2015-2938","CVE-2015-2939","CVE-2015-2940"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0142.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15606"},{"type":"WEB","url":"https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/04/07/3"}],"affected":[{"package":{"name":"mediawiki","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/mediawiki?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.9-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0142.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}