Fedora 9 : mediawiki-1.13.3-42.fc9 (2008-11802)

This script is Copyright (C) 2008-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

This is a security release of MediaWiki 1.13.3. Some of the security
issues affect *all* versions of MediaWiki except the versions released
on Dec. 15th, so all site administrators are encouraged to upgrade.
CVEs assigned to the mentioned MediaWiki update: CVE-2008-5249
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.0 through
1.13.2 allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors. CVE-2008-5250 Cross-site scripting (XSS)
vulnerability in MediaWiki before 1.6.11, 1.12.x before 1.12.2, and
1.13.x before 1.13.3, when Internet Explorer is used and uploads are
enabled, or an SVG scripting browser is used and SVG uploads are
enabled, allows remote authenticated users to inject arbitrary web
script or HTML by editing a wiki page. CVE-2008-5252 Cross-site
request forgery (CSRF) vulnerability in the Special:Import feature in
MediaWiki 1.3.0 through 1.6.10, 1.12.x before 1.12.2, and 1.13.x
before 1.13.3 allows remote attackers to perform unspecified actions
as authenticated users via unknown vectors. As well as other two issue
mentioned in the upstream announcement, treated as security
enhancement rather than vulnerability fixes by upstream: CVE-2008-5687
MediaWiki 1.11 through 1.13.3 does not properly protect against the
download of backups of deleted images, which might allow remote
attackers to obtain sensitive information via requests for files in
images/deleted/. CVE-2008-5688 MediaWiki 1.8.1 through 1.13.3, when
the wgShowExceptionDetails variable is enabled, sometimes provides the
full installation path in a debugging message, which might allow
remote attackers to obtain sensitive information via unspecified
requests that trigger an uncaught exception.

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=476621
http://www.nessus.org/u?baf0e4c6

Solution :

Update the affected mediawiki package.

Risk factor :

Medium / CVSS Base Score : 5.8
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P)
CVSS Temporal Score : 5.0
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Fedora Local Security Checks

Nessus Plugin ID: 35267 (fedora_2008-11802.nasl)

Bugtraq ID: 32844

CVE ID: CVE-2008-5249
CVE-2008-5250
CVE-2008-5252
CVE-2008-5687
CVE-2008-5688

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now