ArchLinux: 201409-4: mediawiki: Cross-site Scripting (XSS)
Summary
It was discovered that MediaWiki, a wiki engine, did not sufficiently filter CSS in uploaded SVG files, allowing for cross site scripting.
Resolution
Upgrade to 1.23.4-1.
# pacman -Syu "mediawiki>=1.23.4-1"
The problem has been fixed upstream in version 1.23.4.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7199 https://phabricator.wikimedia.org/T71008 https://bugs.archlinux.org/task/42161 https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/7CRASJKGBFVXEHSNWKNX3UHOF3IJSBS5/
Workaround
None.