PT-2014-4255 · Wikimedia+1 · Mediawiki+1

Publicado

2014-01-30

·

Atualizado

2016-05-25

·

CVE-2014-1610

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.19.x through 1.19.10 MediaWiki versions 1.21.x through 1.21.4 MediaWiki versions 1.22.x through 1.22.1
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in certain parameters, such as the page parameter to "includes/media/DjVu.php" and the w parameter (also known as the width field) to "thumb.php", which is not properly handled by "includes/media/PdfHandler body.php".
Recommendations For MediaWiki versions 1.19.x through 1.19.10, update to version 1.19.11 or later. For MediaWiki versions 1.21.x through 1.21.4, update to version 1.21.5 or later. For MediaWiki versions 1.22.x through 1.22.1, update to version 1.22.2 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1172
CVE-2014-1610
DSA-2891-1
MGASA-2014-0113

Produtos afetados

Alt Linux
Mediawiki