CVE-2012-4378
Description
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.18.5 and 1.19.x before 1.19.2, when unspecified JavaScript gadgets are used, allow remote attackers to inject arbitrary web script or HTML via the userlang parameter to w/index.php.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4378
Vendor advisory: secalert@redhat.com — https://phabricator.wikimedia.org/T39587
Vendor advisory: secalert@redhat.com — https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html
Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=853417
Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/08/31/6
Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2012/08/31/10
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:1.19.2-1 |
| debian | bullseye | fixed | 1:1.19.2-1 |
| debian | forky | fixed | 1:1.19.2-1 |
| debian | sid | fixed | 1:1.19.2-1 |
| debian | trixie | fixed | 1:1.19.2-1 |
References
- http://www.openwall.com/lists/oss-security/2012/08/31/10
- http://www.openwall.com/lists/oss-security/2012/08/31/6
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330
- https://bugzilla.redhat.com/show_bug.cgi?id=853417
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html
- https://phabricator.wikimedia.org/T39587
- https://security-tracker.debian.org/tracker/CVE-2012-4378
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.