CVE-2015-8005
published 2015-11-09CVE-2015-8005: MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.44%
70.4th percentile
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.25.5-1 (bookworm) | mediawiki 1:1.25.5-1 (bookworm) |
| mediawiki | mediawiki | <= 1.23.10 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-8005: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses th...
vendor_debian·2015·CVSS 5.0
CVE-2015-8005 [MEDIUM] CVE-2015-8005: mediawiki - MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses th...
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.25.5-1)
trixie: resolved (fixed in 1:1.25.5-1)
GHSA
GHSA-2vj4-mfcc-xffc: MediaWiki before 1
ghsa_unreviewed·2022-05-17
CVE-2015-8005 [MEDIUM] CWE-200 GHSA-2vj4-mfcc-xffc: MediaWiki before 1
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
OSV
CVE-2015-8005: MediaWiki before 1
osv·2015-11-09·CVSS 5.0
CVE-2015-8005 [MEDIUM] CVE-2015-8005: MediaWiki before 1
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [fedora-all
bugzilla·2015-10-20·CVSS 3.5
CVE-2015-8001 [LOW] CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [fedora-all
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE I
Bugzilla
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [epel-all]
bugzilla·2015-10-20·CVSS 3.5
CVE-2015-8001 [LOW] CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [epel-all]
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CV
Bugzilla
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11
bugzilla·2015-10-20·CVSS 3.5
CVE-2015-8001 [LOW] CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11
CVE-2015-8001 CVE-2015-8002 CVE-2015-8003 CVE-2015-8004 CVE-2015-8005 CVE-2015-8006 CVE-2015-8007 CVE-2015-8008 CVE-2015-8009 mediawiki: multiple flaws fixed in 1.25.3, 1.24.4, and 1.23.11
Several flaws were found in Mediawiki:
* Wikipedia user RobinHood70 reported that the API failed to correctly stop
adding new chunks to the upload when the reported size was exceeded,
allowing a malicious users to upload add an infinite number of chunks for a
single file upload.
* Wikipedia user RobinHood70 also reported that a malicious user could
upload chunks of 1 byte for very large files, potentially creating a very
large number of files on the server's filesystem.
* Internal review discovered that it is not possible to throttle file
uploads.
* Internal review discovered a missing authorizat
http://www.securitytracker.com/id/1034028https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.htmlhttps://phabricator.wikimedia.org/T108616http://www.securitytracker.com/id/1034028https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.htmlhttps://phabricator.wikimedia.org/T108616
2015-11-09
Published