Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120614013338.GO1540@redhat.com>
Date: Wed, 13 Jun 2012 19:33:38 -0600
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE request: XSS in uselang http parameter (mediawiki)

Mediawiki 1.17.5, 1.18.4, and 1.19.1 were released today to fix a XSS
vulnerability in the useland http parameter.

References:

http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-June/000118.html
https://bugzilla.wikimedia.org/show_bug.cgi?id=36938
https://bugzilla.redhat.com/show_bug.cgi?id=831876

I didn't spot a CVE name in the release, so requesting one here.

Thanks.

-- 
Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.