First published: Fri Sep 29 2006(Updated: )
lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DokuWiki | =release_2006-03-05 | |
DokuWiki | =release_2006-03-09 | |
DokuWiki | =release_2006-03-09e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5098 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
CVE-2006-5098 allows denial of service by causing excessive CPU consumption when large width and height parameters are used for image resizing.
CVE-2006-5098 affects DokuWiki versions prior to release 2006-03-09e.
To mitigate CVE-2006-5098, users should upgrade to at least DokuWiki release 2006-03-09e or later.
If you cannot update DokuWiki, consider implementing input validation to restrict the size of the width and height parameters.