Comment 8 for bug 348858

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mediawiki - 1:1.12.0-2ubuntu0.3

---------------
mediawiki (1:1.12.0-2ubuntu0.3) intrepid-security; urgency=low

  * SECURITY UPDATE: Multiple cross-site scripting (XSS) vulnerabilities in
    the web-based installer (config/index.php). (LP: #348858)
    - CVE-2009-0737
    - debian/patches/CVE-2009-0737.patch
    - patch taken directly from Debian
    - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514547
    - http://lists.wikimedia.org/pipermail/mediawiki-announce/2009-February/000083.html

 -- Andreas Wenning <email address hidden> Thu, 26 Mar 2009 09:33:41 +0100