This bug was fixed in the package mediawiki - 1:1.12.0-2ubuntu0.1
--------------- mediawiki (1:1.12.0-2ubuntu0.1) intrepid-security; urgency=low
* SECURITY UPDATE: Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via the useskin parameter to an unspecified component. (LP: #290015) - debian/patches/CVE-2008-4408.patch: Address XSS vulnerability. Based on upstream/Debian patch. - CVE-2008-4408 - http://svn.wikimedia.org/viewvc/mediawiki?view=rev&revision=41540 - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501115
-- Iain Lane <email address hidden> Mon, 27 Oct 2008 19:27:33 +0000
This bug was fixed in the package mediawiki - 1:1.12.0-2ubuntu0.1
--------------- 0-2ubuntu0. 1) intrepid-security; urgency=low
mediawiki (1:1.12.
* SECURITY UPDATE: patches/ CVE-2008- 4408.patch: Address XSS vulnerability. Based on
upstream/ Debian patch. svn.wikimedia. org/viewvc/ mediawiki? view=rev& revision= 41540 bugs.debian. org/cgi- bin/bugreport. cgi?bug= 501115
Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0,
and possibly other versions before 1.13.2 allows remote attackers
to inject arbitrary web script or HTML via the useskin parameter
to an unspecified component. (LP: #290015)
- debian/
- CVE-2008-4408
- http://
- http://
-- Iain Lane <email address hidden> Mon, 27 Oct 2008 19:27:33 +0000