Summary
The remote host is missing an update to mediawiki
announced via advisory DSA 2022-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202022-1
Insight
Several vulnerabilities have been discovered in mediawiki, a web-based wiki engine. The following issues have been identified:
Insufficient input sanitization in the CSS validation code allows editors to display external images in wiki pages. This can be a privacy concern on public wikis as it allows attackers to gather IP addresses and other information by linking these images to a web server under their control.
Insufficient permission checks have been found in thump.php which can lead to disclosure of image files that are restricted to certain users (e.g. with img_auth.php).
For the stable distribution (lenny), this problem has been fixed in version 1.12.0-2lenny4.
For the testing distribution (squeeze), this problem has been fixed in version 1:1.15.2-1.
For the unstable distribution (sid), this problem has been fixed in version 1:1.15.2-1.
Severity
Classification
-
CVE CVE-2010-1189, CVE-2010-1190 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities