CVE-2014-1610

NameCVE-2014-1610
DescriptionMediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5 and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2891-1
NVD severitymedium (attack range: remote)
Debian/oldstablepackage mediawiki is vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mediawiki (PTS)squeeze (security), squeeze1:1.15.5-2squeeze6vulnerable
wheezy, wheezy (security)1:1.19.20+dfsg-0+deb7u3fixed
jessie, sid1:1.19.20+dfsg-2.2fixed
mediawiki-extensions (PTS)wheezy, wheezy (security)3.5~deb7u2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mediawikisource(unstable)1:1.19.11+dfsg-1medium
mediawikisourcesqueeze(unfixed)end-of-life
mediawikisourcewheezy1:1.19.14+dfsg-0+deb7u1mediumDSA-2891-1
mediawiki-extensionssourcewheezy3.5~deb7u1mediumDSA-2891-1

Search for package or bug name: Reporting problems