SB2013030505 - Fedora EPEL 6 update for mediawiki119
Published: March 5, 2013 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2013-1816)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
2) Information disclosure (CVE-ID: CVE-2013-1817)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Remediation
Install update from vendor's website.