#VU42094 Input validation error in MediaWiki - CVE-2014-1610

 

#VU42094 Input validation error in MediaWiki - CVE-2014-1610

Published: January 31, 2014 / Updated: August 11, 2020


Vulnerability identifier: #VU42094
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2014-1610
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
MediaWiki
Software vendor:
MediaWiki.org

Description

The vulnerability allows a remote #AU# to read and manipulate data.

MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.


Remediation

Install update from vendor's website.

External links