Summary
The remote host is missing an update to mediawiki
announced via advisory FEDORA-2009-7750.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update mediawiki' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-7750
Insight
Update Information:
This update upgrades mediawiki code to 1.15.1 and fixes some path references.
Upstream comments: This is a security and bugfix release of MediaWiki 1.15.1 and 1.14.1. A cross-site scripting (XSS) vulnerability was discovered. Only versions 1.14.0, 1.15.0 and release candidates for those releases are affected.
ChangeLog:
* Mon Jul 13 2009 Axel Thimm - 1.15.1-48
- Update to 1.15.1 (Fixes XSS vulnerability).
* Sat Jul 11 2009 Axel Thimm - 1.15.0-47
- Fix api.php breakage.
* Sat Jun 13 2009 Axel Thimm - 1.15.0-46
- Update to 1.15.0.
* Thu Apr 16 2009 S390x secondary arch maintainer - ExcludeArch sparc64, s390, s390x as we don't have OCaml on those archs (added sparc64 per request from the sparc maintainer) * Sat Feb 28 2009 Axel Thimm - 1.14.0-45
- Update to 1.14.0.
References
Severity
Classification
-
CVE CVE-2008-5249, CVE-2008-5250, CVE-2008-5252, CVE-2008-5687, CVE-2008-5688 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities