FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-1150

This CVE name corresponds to:

Entered Topic
2010-05-05 mediawiki -- authenticated CSRF vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-1150
Phase Assigned(20100329)

Description

MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.

References

Source Reference
MLIST [mediawiki-announce] 20100407 MediaWiki security update: 1.15.3 and 1.16.0beta2
MLIST [oss-security] 20100406 CVE Request: MediaWiki 1.15.3 -- Login CSRF
MLIST [oss-security] 20100407 Re: CVE Request: MediaWiki 1.15.3 -- Login CSRF
CONFIRM http://download.wikimedia.org/mediawiki/1.15/mediawiki-1.15.3.patch.gz
CONFIRM http://download.wikimedia.org/mediawiki/1.16/mediawiki-1.16.0beta2.patch.gz
CONFIRM http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_3/phase3/RELEASE-NOTES
CONFIRM http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_16_0beta2/phase3/RELEASE-NOTES
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=580418
CONFIRM https://bugzilla.wikimedia.org/show_bug.cgi?id=23076
DEBIAN DSA-2041
VUPEN ADV-2010-1055