Vulnerable to information disclosure through various actions

Bug #1955352 reported by Kunal Mehta
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mediawiki (Ubuntu)
Fix Released
Medium
Unassigned
Bionic
In Progress
Medium
Steve Beattie
Focal
In Progress
Medium
Steve Beattie
Hirsute
Won't Fix
Medium
Unassigned
Impish
Won't Fix
Medium
Steve Beattie
Jammy
Fix Released
Medium
Unassigned

Bug Description

The versions of MediaWiki in supported Ubuntu releases are vulnerable to CVE-2021-44857, CVE-2021-44858, and CVE-2021-45038.

See <https://www.mediawiki.org/wiki/2021-12_security_release/FAQ> for more details.

I will upload some debdiffs with patches shortly.

Tags: patch
Revision history for this message
Kunal Mehta (legoktm) wrote :

debdiff for impish

Revision history for this message
Kunal Mehta (legoktm) wrote :
Revision history for this message
Kunal Mehta (legoktm) wrote :

Note that the version in focal is not vulnerable to CVE-2021-44857 nor CVE-2021-45038.

Revision history for this message
Kunal Mehta (legoktm) wrote :

Note the version in bionic is not vulnerable to CVE-2021-44857 nor CVE-2021-45038.

Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "impish.debdiff" seems to be a debdiff. The ubuntu-sponsors team has been subscribed to the bug report so that they can review and hopefully sponsor the debdiff. If the attachment isn't a patch, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are member of the ~ubuntu-sponsors, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issue please contact him.]

tags: added: patch
Revision history for this message
Logan Rosen (logan) wrote :

Removing ~ubuntu-sponsors and subscribing ~ubuntu-security-sponsors, as this should be applied to the security pocket.

Mathew Hodson (mhodson)
information type: Public → Public Security
Changed in mediawiki (Ubuntu):
importance: Undecided → Medium
Revision history for this message
Bryce Harrington (bryce) wrote :

Version in jammy includes the fixes:

mediawiki (1:1.35.5-1) unstable; urgency=high

  [ Kunal Mehta ]
  * New upstream version 1.35.5, fixing CVE-2021-44854, CVE-2021-44855,
    CVE-2021-44856, CVE-2021-44857, CVE-2021-44858, CVE-2021-45038.

  [ Debian Janitor ]
  * Remove constraints unnecessary since buster

 -- Kunal Mehta <email address hidden> Thu, 30 Sep 2021 20:42:36 -0700

Changed in mediawiki (Ubuntu Jammy):
status: New → Fix Released
Mathew Hodson (mhodson)
Changed in mediawiki (Ubuntu Bionic):
importance: Undecided → Medium
Changed in mediawiki (Ubuntu Focal):
importance: Undecided → Medium
Changed in mediawiki (Ubuntu Hirsute):
importance: Undecided → Medium
Changed in mediawiki (Ubuntu Impish):
importance: Undecided → Medium
Revision history for this message
Brian Murray (brian-murray) wrote :

The Hirsute Hippo has reached End of Life, so this bug will not be fixed for that release.

Changed in mediawiki (Ubuntu Hirsute):
status: New → Won't Fix
Revision history for this message
Steve Beattie (sbeattie) wrote :

Hi Kunal,

Thanks for preparing these updates, I'm looking at them now. Apologies that they didn't get picked up earlier.

Changed in mediawiki (Ubuntu Bionic):
assignee: nobody → Steve Beattie (sbeattie)
Changed in mediawiki (Ubuntu Focal):
assignee: nobody → Steve Beattie (sbeattie)
Changed in mediawiki (Ubuntu Impish):
assignee: nobody → Steve Beattie (sbeattie)
Changed in mediawiki (Ubuntu Bionic):
status: New → In Progress
Changed in mediawiki (Ubuntu Focal):
status: New → In Progress
Changed in mediawiki (Ubuntu Impish):
status: New → In Progress
Revision history for this message
Steve Beattie (sbeattie) wrote :

Hey Kunal, thanks again for preparing these debdiffs. After reviewing them, I've gone ahead and uploaded the packages to the ubuntu-security-proposed ppa at https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages to build and run through autopkgtests; any feedback or additional testing you or anyone can give would be greatly appreciated.

Thanks again.

Revision history for this message
Brian Murray (brian-murray) wrote :

Ubuntu 21.10 (Impish Indri) has reached end of life, so this bug will not be fixed for that specific release.

Changed in mediawiki (Ubuntu Impish):
status: In Progress → Won't Fix
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Hi,

Packages have been in the security team PPA for months now. Could the bug reporter please test the proposed packages so we can release them? Thanks!

Revision history for this message
Julian Andres Klode (juliank) wrote :

It's been another month where this has been waiting on testing from the bug reporter. I don't think there's anything to sponsor here right now and would suggest unsubscribing security sponsors.

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

I asked in #ubuntu-security to have someone unsubscribe ubuntu-security-sponsors from this bug, as there is nothing to sponsor.

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

I tried to match the sponsored patch with the upstream commits, and it's very confusing. I'm not sure I would have sponsored that as-is, at least not without further explanations.

The upstream security announcement[1] lists 5 CVEs, with 5 associated upstream bugs, but the patch in the sponsored package only mentions CVE-44854. Furthermore, the patch mentions that CVE together with upstream bug T297322[2], but the same CVE is also associated with another upstream bug T292763[3], which seems to have a different patch. I.e., are there fixes missing? What about these?

* https://phabricator.wikimedia.org/T294686
* https://phabricator.wikimedia.org/T293589
* https://phabricator.wikimedia.org/T271037

1. https://www.mediawiki.org/wiki/2021-12_security_release/FAQ
2. https://phabricator.wikimedia.org/T297322
3. https://phabricator.wikimedia.org/T292763

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.