mediawiki 1.19.3 fixes security vulnerability (CVE-2012-5391)

Bug #1090040 reported by Jeremy Bícha
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mediawiki (Debian)
Fix Released
Unknown
mediawiki (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-November/000122.html

* During an internal review, it was discovered that MediaWiki core is
vulnerable to session fixation attacks. Successful exploitation could
allow an attacker to compromise another user's account. This issue
has been assigned CVE-2012-5391.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=40995>

* Wikipedia user PleaseStand discovered that a PCRE backtrack limit
could easily be exceeded, causing recent changes and history pages to
fail to display. Since these pages are often used for fighting spam
and vandalism, public wikis are encouraged to update.
<https://bugzilla.wikimedia.org/show_bug.cgi?id=41400>

MediaWiki 1.19 is a "Long Term Support" release so it would be good if we would take their updates.
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-November/000120.html

ProblemType: Bug
DistroRelease: Ubuntu 13.04
Package: mediawiki 1:1.19.2-2
ProcVersionSignature: Ubuntu 3.7.0-5.13-generic 3.7.0-rc8
Uname: Linux 3.7.0-5-generic x86_64
ApportVersion: 2.7-0ubuntu2
Architecture: amd64
Date: Thu Dec 13 12:30:11 2012
MarkForUpload: True
PackageArchitecture: all
SourcePackage: mediawiki
UpgradeStatus: No upgrade log present (probably fresh install)
modified.conffile..etc.mediawiki.apache.conf: [modified]
mtime.conffile..etc.mediawiki.apache.conf: 2012-11-15T14:56:52.907917

CVE References

Revision history for this message
Jeremy Bícha (jbicha) wrote :
Changed in mediawiki (Ubuntu):
status: New → Fix Released
Revision history for this message
Jeremy Bícha (jbicha) wrote :

Fixed in raring:

 mediawiki (1:1.19.3-1) unstable; urgency=high
 .
   [ Dominik George ]
   * Team upload
   * New upstream version fixes security issues (Closes: #694998)
     + Prevent session fixation in Special:UserLogin (CVE-2012-5391)
       https://bugzilla.wikimedia.org/show_bug.cgi?id=40995
     + Prevent linker regex from exceeding PCRE backtrack limit
       https://bugzilla.wikimedia.org/show_bug.cgi?id=41400
 .
   [ Thorsten Glaser ]
   * Fix spelling error in README.Debian (thanks lintian!)

Changed in mediawiki (Debian):
status: Unknown → Fix Released
no longer affects: mediawiki (Ubuntu Quantal)
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.