CVE-2017-0367
published 2018-04-13CVE-2017-0367: Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is…
PriorityP341high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.86%
77.0th percentile
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.27.2-1 (bookworm) | mediawiki 1:1.27.2-1 (bookworm) |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| mediawiki | mediawiki | >= 1.27.0 < 1.27.2 | 1.27.2 |
| mediawiki | mediawiki | >= 1.28.0 < 1.28.1 | 1.28.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mediawiki: unsafe use of temporary directory
vendor_redhat·2017-03-26·CVSS 8.8
CVE-2017-0367 [HIGH] CWE-377 mediawiki: unsafe use of temporary directory
mediawiki: unsafe use of temporary directory
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Package: mediawiki123 (Red Hat OpenShift Enterprise 3) - Affected
Debian
CVE-2017-0367: mediawiki - Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, ...
vendor_debian·2017·CVSS 8.8
CVE-2017-0367 [HIGH] CVE-2017-0367: mediawiki - Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, ...
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
GHSA
GHSA-jqmm-c922-3758: Mediawiki before 1
ghsa_unreviewed·2022-05-13
CVE-2017-0367 [HIGH] CWE-668 GHSA-jqmm-c922-3758: Mediawiki before 1
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
OSV
CVE-2017-0367: Mediawiki before 1
osv·2018-04-13·CVSS 8.8
CVE-2017-0367 [HIGH] CVE-2017-0367: Mediawiki before 1
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0367 mediawiki: unsafe use of temporary directory
bugzilla·2018-04-20·CVSS 8.8
CVE-2017-0367 [HIGH] CVE-2017-0367 mediawiki: unsafe use of temporary directory
CVE-2017-0367 mediawiki: unsafe use of temporary directory
A flaw was found in Mediawiki before 1.28.1 / 1.27.2. Affected versions contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
References:
https://phabricator.wikimedia.org/T161453
https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.html
Talos
Vulnerability Spotlight: Iceni Infix PDF Editor Memory Corruption
blogs_talos·2017-07-11·CVSS 7.8
[HIGH] Vulnerability Spotlight: Iceni Infix PDF Editor Memory Corruption
Today, Talos is disclosing a vulnerability that has been identified in Iceni Infix PDF Editor that could lead to arbitrary code execution on affected hosts. This vulnerability manifests in a way that could be exploited if a user opens a specifically crafted PDF file that triggers this flaw. Talos has coordinated with Iceni to ensure relevant details regarding the vulnerability have been shared. Iceni has developed a software update that addresses this vulnerability. In addition, Talos has developed Snort Rules that can detect attempts to exploit this flaw.
## Vulnerability Details TALOS-2017-0367 was identified by Piotr Bania of Talos.
TALOS-2017-0367 (CVE-2017-2863) is memory corruption vulnerability in Iceni Infix that could be leveraged to achieve arbitrary code execution on the affec
Talos
Vulnerability Spotlight: Iceni Infix PDF Editor Memory Corruption
blogs_talos·2017-07-11·CVSS 7.8
[HIGH] Vulnerability Spotlight: Iceni Infix PDF Editor Memory Corruption
## Vulnerability Spotlight: Iceni Infix PDF Editor Memory Corruption
Today, Talos is disclosing a vulnerability that has been identified in Iceni Infix PDF Editor that could lead to arbitrary code execution on affected hosts. This vulnerability manifests in a way that could be exploited if a user opens a specifically crafted PDF file that triggers this flaw. Talos has coordinated with Iceni to ensure relevant details regarding the vulnerability have been shared. Iceni has developed a software update that addresses this vulnerability. In addition, Talos has developed Snort Rules that can detect attempts to exploit this flaw.
## Vulnerability Details TALOS-2017-0367 was identified by Piotr Bania of Talos.
TALOS-2017-0367 (CVE-2017-2863) is memory corruption vulnerability in Iceni Infix th
https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.htmlhttps://phabricator.wikimedia.org/T161453https://security-tracker.debian.org/tracker/CVE-2017-0367https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.htmlhttps://phabricator.wikimedia.org/T161453https://security-tracker.debian.org/tracker/CVE-2017-0367
2018-04-13
Published