Mandriva Linux Security Advisory : mediawiki (MDVSA-2013:290)
Medium Nessus Plugin ID 71510
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionUpdated mediawiki packages fix security vulnerabilities :
Internal review while debugging a site issue discovered that MediaWiki and the CentralNotice extension were incorrectly setting cache headers when a user was autocreated, causing the user's session cookies to be cached, and returned to other users (CVE-2013-4572).
SolutionUpdate the affected packages.