CVE-2013-6452

NameCVE-2013-6452
DescriptionCross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2891-1
NVD severitymedium (attack range: remote, user-initiated)
Debian/oldoldstablepackage mediawiki is vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mediawiki (PTS)squeeze, squeeze (security)1:1.15.5-2squeeze6vulnerable
wheezy (security), wheezy1:1.19.20+dfsg-0+deb7u3fixed
sid, jessie1:1.19.20+dfsg-2.3fixed
mediawiki-extensions (PTS)wheezy (security), wheezy3.5~deb7u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mediawikisource(unstable)1:1.19.10+dfsg-1medium
mediawikisourcesqueeze(unfixed)end-of-life
mediawikisourcewheezy1:1.19.14+dfsg-0+deb7u1mediumDSA-2891-1
mediawiki-extensionssourcewheezy3.5~deb7u1mediumDSA-2891-1

Notes

https://bugzilla.wikimedia.org/show_bug.cgi?id=57550

Search for package or bug name: Reporting problems