Описание
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 1:1.27.4-3 |
| cosmic | not-affected | 1:1.31.1-3 |
| devel | not-affected | 1:1.31.1-3 |
| disco | not-affected | 1:1.31.1-3 |
| esm-apps/bionic | not-affected | 1:1.27.4-3 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needs-triage |
| trusty | ignored | end of standard support |
Показывать по
5 Medium
CVSS2
Связанные уязвимости
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25 ...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
5 Medium
CVSS2