Bug#696179: [Pkg-mediawiki-devel] Bug#696179: mediawiki-extensions-base: RSS_Reader Javascript injection

2012-12-31 Thread Thorsten Glaser
cve-ass...@mitre.org dixit: See http://bugs.debian.org/696179 for details. Use CVE-2012-6453. Ok, thanks! Forwarding to all parties: this is DSA-2596-1 for mediawiki-extensions. bye, //mirabilos -- I want one of these. They cost 720 € though… good they don’t have the HD hole, which indicates

Bug#696179: [Pkg-mediawiki-devel] Bug#696179: mediawiki-extensions-base: RSS_Reader Javascript injection

2012-12-19 Thread Thorsten Glaser
Dixi quod… Of course, this will not work on the message body. I’ll look at Ok, it’s worse than I expected: when using “text” mode with desc=on, the body is also vulnerable but on the other hand, proper HTML is broken: ‣ pWill drive to a

Bug#696179: [Pkg-mediawiki-devel] Bug#696179: mediawiki-extensions-base: RSS_Reader Javascript injection

2012-12-17 Thread Thorsten Glaser
On Mon, 17 Dec 2012, Jonathan Wiltshire wrote: At a quick glance this appears to affect upstream Can you confirm this Yes, it does. have you sought out a CVE number? No, I’ve got no idea how all this CVE stuff works. Do you volunteer, or one of the Mediawiki guys lurking here? Otherwise

Bug#696179: [Pkg-mediawiki-devel] Bug#696179: mediawiki-extensions-base: RSS_Reader Javascript injection

2012-12-17 Thread Thorsten Glaser
On Mon, 17 Dec 2012, Platonides wrote: http://www.mediawiki.org/wiki/Extension:RSS_Reader seems to live exclusively at the wiki page, instead of being at a repository. […] Just edit the page when fixing the bug. Oh, okay. I just did so. On Mon, 17 Dec 2012, Jonathan Wiltshire wrote: (for