Bug 29772 - mediawiki new security issues CVE-2021-4485[4-8] and CVE-2021-45038
Summary: mediawiki new security issues CVE-2021-4485[4-8] and CVE-2021-45038
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-12-16 19:52 CET by David Walser
Modified: 2021-12-19 13:27 CET (History)
3 users (show)

See Also:
Source RPM: mediawiki-1.35.4-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-12-16 19:52:07 CET
Debian has issued an advisory on December 15:
https://www.debian.org/security/2021/dsa-5021

These issues and others are fixed upstream in 1.35.5:
https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/QEN3EK4JXAVJMJ5GF3GYOAKNJPEKFQYA/

Updated packages uploaded for Mageia 8 and Cauldron.

Updated packages in core/updates_testing:
========================
mediawiki-sqlite-1.35.5-1.mga8
mediawiki-mysql-1.35.5-1.mga8
mediawiki-pgsql-1.35.5-1.mga8
mediawiki-1.35.5-1.mga8

from SRPM:
mediawiki-1.35.5-1.mga8.src.rpm
Comment 1 Herman Viaene 2021-12-17 15:28:32 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
For future reference, first remove the old wiki as stated in the wiki before installing!!!!
No installation issues.
Ref bug 27781
Make sure httpd and mysqld are running.
# systemctl start httpd
# systemctl start mysqld
Then created the user and database along the lines of the wiki, using phpMyadmin, then the rest of the wiki. All works OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 2 Thomas Andrews 2021-12-18 19:51:09 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Thomas Backlund 2021-12-19 11:54:16 CET

Keywords: (none) => advisory

Comment 3 Mageia Robot 2021-12-19 13:27:48 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0568.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.