CVE-2013-1816
published 2019-11-20CVE-2013-1816: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.68%
84.1th percentile
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.19.4-1 (bookworm) | mediawiki 1:1.19.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.19.4 | 1.19.4 |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 1.20.0 < 1.20.3 | 1.20.3 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g7xp-g555-2g9m: MediaWiki before 1
ghsa_unreviewed·2022-05-05
CVE-2013-1816 [MEDIUM] GHSA-g7xp-g555-2g9m: MediaWiki before 1
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
OSV
CVE-2013-1816: MediaWiki before 1
osv·2019-11-20·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816: MediaWiki before 1
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Debian
CVE-2013-1816: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to caus...
vendor_debian·2013·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to caus...
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Scope: local
bookworm: resolved (fixed in 1:1.19.4-1)
bullseye: resolved (fixed in 1:1.19.4-1)
forky: resolved (fixed in 1:1.19.4-1)
sid: resolved (fixed in 1:1.19.4-1)
trixie: resolved (fixed in 1:1.19.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for mediawiki119
Bugzilla
CVE-2013-1816 MediaWiki: Pass '2' instead of 'true' to CURLOPT_SSL_VERIFYHOST
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816 MediaWiki: Pass '2' instead of 'true' to CURLOPT_SSL_VERIFYHOST
CVE-2013-1816 MediaWiki: Pass '2' instead of 'true' to CURLOPT_SSL_VERIFYHOST
MediaWiki reports:
(bug 44135/bug 42441) Pass '2' instead of 'true' to CURLOPT_SSL_VERIFYHOST
https://bugzilla.wikimedia.org/show_bug.cgi?id=44135
https://bugzilla.wikimedia.org/show_bug.cgi?id=42441
Discussion:
Created mediawiki119 tracking bugs for this issue
Affects: epel-6 [bug 917919]
---
Created mediawiki119 tracking bugs for this issue
Affects: fedora-18 [bug 917920]
---
mediawiki119-1.19.4-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for mediawiki11
http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/03/05/4http://www.securityfocus.com/bid/58306https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1816https://exchange.xforce.ibmcloud.com/vulnerabilities/88360https://security-tracker.debian.org/tracker/CVE-2013-1816http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/03/05/4http://www.securityfocus.com/bid/58306https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1816https://exchange.xforce.ibmcloud.com/vulnerabilities/88360https://security-tracker.debian.org/tracker/CVE-2013-1816
2019-11-20
Published