Input validation error in MediaWiki - CVE-2014-1610

 

Input validation error in MediaWiki - CVE-2014-1610

Published: January 31, 2014 / Updated: August 11, 2020


Vulnerability identifier: #VU42094
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1610
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.


Affected software

MediaWiki
Gentoo Linux
Fedora
mediawiki119

How to mitigate CVE-2014-1610

Install update from vendor's website.

mediawiki119 - addressed in versions 1.19.11-2.el5, 1.19.11-2.el6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins