Bug 26921 - mediawiki new security issue fixed upstream in 1.31.8
Summary: mediawiki new security issue fixed upstream in 1.31.8
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, has_procedure, validated_update
Depends on:
Blocks:
 
Reported: 2020-07-08 00:41 CEST by David Walser
Modified: 2020-07-10 17:41 CEST (History)
4 users (show)

See Also:
Source RPM: mediawiki-1.31.7-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-07-08 00:41:19 CEST
Upstream has announced version 1.31.8 on June 24:
https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-June/000252.html

It fixes one security issue.

Fedora has issued an advisory for this on July 5:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/EEZIMLJMJS72SJXPYL736XMUAVCRQD2H/

Updated packages uploaded for Mageia 7 and Cauldron.

Advisory:
========================

Updated mediawiki packages fix security vulnerability:

In MediaWiki before 1.31.8, private wikis behind a caching server using the
img_auth.php image authorization security feature may have had their files
cached publicly, so any unauthorized user could view them. This occurs because
Cache-Control and Vary headers were mishandled (CVE-2020-15005).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15005
https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-June/000252.html
========================

Updated packages in core/updates_testing:
========================
mediawiki-1.31.8-1.mga7
mediawiki-mysql-1.31.8-1.mga7
mediawiki-pgsql-1.31.8-1.mga7
mediawiki-sqlite-1.31.8-1.mga7

from mediawiki-1.31.8-1.mga7.src.rpm
Comment 1 David Walser 2020-07-08 00:41:58 CEST
Testing procedure:
https://wiki.mageia.org/en/QA_procedure:Mediawiki

Keywords: (none) => has_procedure

Comment 2 Herman Viaene 2020-07-08 15:29:55 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref bug 25986.
Started httpd and mysqld and then followed wiki up to creating a new wiki and a new page in it (trick: there is no "New" button, just type a name in the search box, it will not find it, but then you can create it).
Works OK.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => herman.viaene

Comment 3 Thomas Andrews 2020-07-08 21:15:56 CEST
Validating. Advisory in Comment 0.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Nicolas Lécureuil 2020-07-10 16:59:21 CEST

Keywords: (none) => advisory
CC: (none) => mageia

Comment 4 Mageia Robot 2020-07-10 17:41:26 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0292.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.