oss-sec mailing list archives

Re: CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS


From: cve-assign () mitre org
Date: Thu, 2 Oct 2014 13:05:13 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html
https://bugzilla.wikimedia.org/show_bug.cgi?id=70672
(bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance.
https://gerrit.wikimedia.org/r/#/c/164271/

No longer segment module origin allowance

It seems best to assign only one CVE ID for the availability of CSS
in an apparently unintended context, with resultant impacts of both
XSS and UI redressing. Use CVE-2014-7295.


While at it, also remove the ability to set the module allowance directly.

This change seems to be about eliminating unused and possibly
confusing functionality, not a separate vulnerability fix.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJULYVrAAoJEKllVAevmvms9wMH/0z2JxQOGiKWh6m7opKgeBEK
Z/9hLV0dmmLdXGnBo2o3HK/J0h1bYklT6+TEdQ1ESJ4EIHlejB7WsUnQY4XlSlzA
LtqFxRIBhbwVOdv+UGgdZXfNGaPoMflZqa1KSYa6vb9rIxoc3CPglM/59qSc6XCN
3Xr3mu8E9fbNT7YsZeatVhzxUh6QYHJ5JpOx7z/xiwGNqZfDqqb/eh4p70FcVPY6
bsykRXmmOwLIujsn47gSCW+g383F4vTFj7AyhIDahZXOWbm4hwJJWG6mi/MWsd3L
/nIfzN6UQfSu6EFuMLDg1+/qfJPWi9kzal/XtTG3zu54DKRqedn5UZ/EdxzrbGE=
=iYhQ
-----END PGP SIGNATURE-----


Current thread: