CVE-2012-4885
published 2012-09-09CVE-2012-4885: The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.88%
77.2th percentile
The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.0-1 (bookworm) | mediawiki 1:1.19.0-1 (bookworm) |
| drupal | drupal | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.19.0-1 | 1:1.19.0-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.0-1 | 1:1.19.0-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.0-1 | 1:1.19.0-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.0-1 | 1:1.19.0-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw9f-6pvh-rr9x: The wikitext parser in MediaWiki 1
ghsa_unreviewed·2022-05-17
CVE-2012-4885 [MEDIUM] GHSA-cw9f-6pvh-rr9x: The wikitext parser in MediaWiki 1
The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
OSV
CVE-2012-4885: The wikitext parser in MediaWiki 1
osv·2012-09-09·CVSS 5.0
CVE-2012-4885 [MEDIUM] CVE-2012-4885: The wikitext parser in MediaWiki 1
The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
Red Hat
php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
vendor_redhat·2012-02-02·CVSS 5.0
CVE-2012-0830 [MEDIUM] CWE-228 php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.
Drupal
Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
vendor_drupal·2012-01-11·CVSS 5.0
CVE-2011-4885 [MEDIUM] Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
Title: Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
Vulnerability Type: Hash DOS attack prevention with Suhosin needs a .htaccess edit
Description: Advisory ID: DRUPAL-PSA-2012-001 Project: Drupal core Version: 6.x, 7.x Date: 2012-01-11 Security risk: Less critical Exploitable from: Remote Vulnerability: Denial of Service Description Update, June 12th 2012: this advisory is related to flaws in PHP with CVE identifiers CVE-2011-4885 and CVE-2012-0830. Users are encouraged to update the PHP used for their site to a version that is known to fix those vulnerabilities. See below for mitigation techniques if your site runs a version of PHP that doesn't contain those fixes and you cannot change it. PHP is vulnerable to a hash collision denial of service (DOS) at
Debian
CVE-2012-4885: mediawiki - The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 a...
vendor_debian·2012·CVSS 5.0
CVE-2012-4885 [MEDIUM] CVE-2012-4885: mediawiki - The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 a...
The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
Scope: local
bookworm: resolved (fixed in 1:1.19.0-1)
bullseye: resolved (fixed in 1:1.19.0-1)
forky: resolved (fixed in 1:1.19.0-1)
sid: resolved (fixed in 1:1.19.0-1)
trixie: resolved (fixed in 1:1.19.0-1)
No detection rules found.
No public exploits indexed.
http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.htmlhttp://secunia.com/advisories/48504http://www.openwall.com/lists/oss-security/2012/03/22/9http://www.openwall.com/lists/oss-security/2012/03/24/1http://www.securityfocus.com/bid/52689https://bugzilla.wikimedia.org/show_bug.cgi?id=22555https://bugzilla.wikimedia.org/show_bug.cgi?id=35315http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.htmlhttp://secunia.com/advisories/48504http://www.openwall.com/lists/oss-security/2012/03/22/9http://www.openwall.com/lists/oss-security/2012/03/24/1http://www.securityfocus.com/bid/52689https://bugzilla.wikimedia.org/show_bug.cgi?id=22555https://bugzilla.wikimedia.org/show_bug.cgi?id=35315
2012-09-09
Published