You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa mediawiki

Sigurnosni nedostaci programskog paketa mediawiki

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2020-12-27 01:38:17.458696

Name : mediawiki
Product : Fedora 33
Version : 1.35.1
Release : 1.fc33
Summary : A wiki engine
Description :
MediaWiki is the software used for Wikipedia and the other Wikimedia
Foundation websites. Compared to other wikis, it has an excellent
range of features and support for high-traffic websites using multiple

This package supports wiki farms. Read the instructions for creating wiki
instances under /usr/share/doc/mediawiki/README.RPM.
Remember to remove the config dir after completing the configuration.

Update Information:

* Fri Dec 18 2020 Michael Cronenworth <> – 1.35.1-1
– Update to 1.35.1

[ 1 ] Bug #1908930 – mediawiki-1.35.1 is available
[ 2 ] Bug #1909225 – CVE-2020-35475 mediawiki: messages userrights-expiry-current and userrights-expiry-none can contain raw html [fedora-all]
[ 3 ] Bug #1909228 – CVE-2020-35474 mediawiki: message recentchanges-legend-watchlistexpiry can contain raw html [fedora-all]
[ 4 ] Bug #1909232 – CVE-2020-35477 mediawiki: unable to change visibility of log entries when MediaWiki:Mainpage uses Special:MyLanguage [fedora-all]
[ 5 ] Bug #1909235 – CVE-2020-35478 mediawiki: potential XSS via MediaWiki:blanknamespace outputting Block Logs [fedora-all]
[ 6 ] Bug #1909238 – CVE-2020-35479 mediawiki: potential XSS via the month messages such as MediaWiki:january through MediaWiki:december outputting Block Logs [fedora-all]
[ 7 ] Bug #1909241 – CVE-2020-35480 mediawiki: divergent behavior for contributions and user pages of hidden users and missing users [fedora-all]

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2020-0be2d40e13’ at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list —
To unsubscribe send an email to
Fedora Code of Conduct:
List Guidelines:
List Archives:

Cert idNCERT-REF-2020-12-0001-ADV
More in Preporuke
Sigurnosni nedostatak programskog paketa kitty

Otkriven je sigurnosni nedostatak u programskom paketu kitty za operacijski sustav Debian. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...