Solution: Update to MediaWiki 1.13.3, 1.12.3 and 1.6.11 or apply patches. See vendor advisory for more details.
Note: Patch 1.12.3 has been released to fix various missing files in the 1.12.2 patch.
Additionally, the 1.13.3 patch has been re-released to include the missing file includes/IEContentAnalyzer.php. Download and apply the patch again or download the missing file from SVN: http://svn.wikimedia.org/viewvc/media.../IEContentAnalyzer.php?revision=44506
Provided and/or discovered by: The vendor partially credits David Remahl, Apple's Product Security.
Further information provided by the vendor.
Changelog: 2008-12-17: Updated "Solution" section to include correct version number and new information about version 1.12.2. Added new link to "Original Advisory" section.
2008-12-18: Updated "Solution" section to include new information about version 1.12.3 and re-released version 1.13.3. Added new link to "Original Advisory" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.