MGASA-2015-0421

Source
https://advisories.mageia.org/MGASA-2015-0421.html
Import Source
https://advisories.mageia.org/MGASA-2015-0421.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0421
Related
Published
2015-11-02T20:21:29Z
Modified
2015-11-02T20:12:45Z
Summary
Updated mediawiki packages fix security vulnerabilities
Details

Updated mediawiki packages fix security vulnerabilities:

In MediaWiki before 1.23.11, the API failed to correctly stop adding new chunks to the upload when the reported size was exceeded, allowing a malicious user to upload add an infinite number of chunks for a single file upload (CVE-2015-8001).

In MediaWiki before 1.23.11, a malicious user could upload chunks of 1 byte for very large files, potentially creating a very large number of files on the server's filesystem (CVE-2015-8002).

In MediaWiki before 1.23.11, it is not possible to throttle file uploads, or in other words, rate limit them (CVE-2015-8003).

In MediaWiki before 1.23.11, a missing authorization check when removing suppression from a revision allowed users with the 'viewsuppressed' user right but not the appropriate 'suppressrevision' user right to unsuppress revisions (CVE-2015-8004).

In MediaWiki before 1.23.11, thumbnails of PNG files generated with ImageMagick contained the local file path in the image (CVE-2015-8005).

References
Credits

Affected packages

Mageia:5 / mediawiki

Package

Name
mediawiki
Purl
pkg:rpm/mageia/mediawiki?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.23.11-1.mga5

Ecosystem specific

{
    "section": "core"
}