[Secure-testing-commits] r23554 - data/CVE

Salvatore Bonaccorso carnil at alioth.debian.org
Thu Sep 5 07:05:30 UTC 2013


Author: carnil
Date: 2013-09-05 07:05:30 +0000 (Thu, 05 Sep 2013)
New Revision: 23554

Modified:
   data/CVE/list
Log:
Add remaining mediawiki CVEs

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2013-09-05 06:19:18 UTC (rev 23553)
+++ data/CVE/list	2013-09-05 07:05:30 UTC (rev 23554)
@@ -2924,16 +2924,22 @@
 	RESERVED
 CVE-2013-4309
 	RESERVED
-CVE-2013-4308
+CVE-2013-4308 [LiquidThreads XSS]
 	RESERVED
-CVE-2013-4307
+	NOT-FOR-US: Mediawiki LiquidThreads extension
+CVE-2013-4307 [Wikibase XSS]
 	RESERVED
-CVE-2013-4306
+	NOT-FOR-US: Mediawiki Wikibase
+CVE-2013-4306 [CheckUser CSRF bypass]
 	RESERVED
-CVE-2013-4305
+	NOT-FOR-US: Mediawiki CheckUser extension
+CVE-2013-4305 [mediawiki SyntaxHighlight_GeSHi XSS]
 	RESERVED
-CVE-2013-4304
+	- mediawiki-extensions <unfixed>
+	TODO: check
+CVE-2013-4304 [mediawiki CentralAuth auth bypass]
 	RESERVED
+	NOT-FOR-US: Mediawiki CentralAuth extension
 CVE-2013-4303 [mediawiki XSS with IE6]
 	RESERVED
 	- mediawiki <unfixed> (unimportant)




More information about the Secure-testing-commits mailing list