PT-2012-5637 · Wikimedia · Mediawiki
Bawolff
·
Published
2012-09-09
·
Updated
2012-09-10
·
CVE-2012-4885
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions 1.17.x through 1.17.2
MediaWiki versions 1.18.x through 1.18.1
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, via certain input to the wikitext parser, as demonstrated by the padleft function.
Recommendations
For MediaWiki versions 1.17.x through 1.17.2, update to version 1.17.3 or later.
For MediaWiki versions 1.18.x through 1.18.1, update to version 1.18.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mediawiki