[ GLSA 202107-40 ] MediaWiki: Multiple vulnerabilities

John Helmert III <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <[email protected]>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202107-40
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Low
    Title: MediaWiki: Multiple vulnerabilities
     Date: July 17, 2021
     Bugs: #780654, #797661
       ID: 202107-40

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in MediaWiki, the worst of
which could result in a Denial of Service condition.

Background
==========

MediaWiki is a collaborative editing software used by large projects
such as Wikipedia.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  www-apps/mediawiki           < 1.36.1                  >= 1.36.1 

Description
===========

Multiple vulnerabilities have been discovered in MediaWiki. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All MediaWiki users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=www-apps/mediawiki-1.36.1"

References
==========

[ 1 ] CVE-2021-30152
      https://nvd.nist.gov/vuln/detail/CVE-2021-30152
[ 2 ] CVE-2021-30154
      https://nvd.nist.gov/vuln/detail/CVE-2021-30154
[ 3 ] CVE-2021-30155
      https://nvd.nist.gov/vuln/detail/CVE-2021-30155
[ 4 ] CVE-2021-30157
      https://nvd.nist.gov/vuln/detail/CVE-2021-30157
[ 5 ] CVE-2021-30158
      https://nvd.nist.gov/vuln/detail/CVE-2021-30158
[ 6 ] CVE-2021-30159
      https://nvd.nist.gov/vuln/detail/CVE-2021-30159
[ 7 ] CVE-2021-30458
      https://nvd.nist.gov/vuln/detail/CVE-2021-30458
[ 8 ] CVE-2021-35197
      https://nvd.nist.gov/vuln/detail/CVE-2021-35197

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202107-40

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmDyZtAACgkQXP0dAeB+
Izg+ZA/9E5CTJHWJc371u7oNWpi9RlM+eoKcnOaDrWwkkfGW4V23z5no2TCVBNUD
7yAbF0ZVSLoNvg7xtDlpFTZMz+BzNl5MlIYJKzgwyj16ncNIzED1C2UDfzTjOIB6
k1++NnnD7XLBW32LtPosvktzV7t+k4VvYndKsJGvNVT9LgV6wRQWm56DJypD99VX
qz2eSFlKFUEyJsFCtwB0aNick+eEne5rC7cAvtvo4CL1vAOFdrkr91cRHa5nMMeA
dR81xvtoZajHxHGaSxMks8xKZyrqxGzi17pI3rovbjVJxBjIYlO52B5k7bOyyAZs
lEtjtzSifNsnqbAy+o8ZG47CM64o7iagmrmAkx4lVwsYlcTG6mQ0MU6bJsNhSDBN
wx9Eg681OopB6onOm38QW6fHU2PIkTiQwx8ETpP/iU3y0014qJcGZW98a7F8H4Eb
9RxeC6nRISdgwe9x4UBaSDmcYTiNn2CdSBcn5Cy9kezfy5XbTeYKUeobfNVaya3r
Zd2cQ84Cq1K3vegkmY9yukQOq9U5SICygbWL85XPXnagqB+iyMZb3SJDbB/V5/Vj
zxtw0HrTyzrwcanpQNDxhVjAzyDZKPUUfzJt7d3Ls9eh9JoxH80iXkQXajOCbnXb
xb3FqvNpexhhyiIgVTvPTcppz+/2Iuar69UDMwZp03vvCXViwDE=
=8nED
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.