CVE-2012-6330: Medium severity twiki vulnerability
Published Jan 4, 2013
·Updated
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.
Affected Software
16 affected components
Twiki TWiki<=5.1.2
Twiki TWiki=5.1.0
Twiki TWiki=5.1.1
Foswiki Foswiki=1.0.0
Foswiki Foswiki=1.0.1
Foswiki Foswiki=1.0.2
Foswiki Foswiki=1.0.3
Foswiki Foswiki=1.0.4
Foswiki Foswiki=1.0.10
Foswiki Foswiki=1.1.0
Foswiki Foswiki=1.1.1
Foswiki Foswiki=1.1.2
Foswiki Foswiki=1.1.3
Foswiki Foswiki=1.1.4
Foswiki Foswiki=1.1.5
Foswiki Foswiki=1.1.6
Event History
Jan 4, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6330?
The severity of CVE-2012-6330 is classified as moderate due to its potential to cause denial of service.
2
How do I fix CVE-2012-6330?
To fix CVE-2012-6330, upgrade to TWiki version 5.1.3 or later, or Foswiki version 1.1.7 or later.
3
What versions are affected by CVE-2012-6330?
CVE-2012-6330 affects TWiki versions prior to 5.1.3 and Foswiki versions 1.0.x through 1.0.10 and 1.1.x through 1.1.6.
4
What type of vulnerability is CVE-2012-6330?
CVE-2012-6330 is a denial-of-service vulnerability that affects the localization functionality.
5
Who can exploit CVE-2012-6330?
CVE-2012-6330 can be exploited by remote attackers using specially crafted input.