CVE-2013-4570: Null Pointer Dereference
The zendinlinehashfunc function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to converting Lua data structures to PHP, as demonstrated by passing { [{}] = 1 } to a module function.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4570?
The severity of CVE-2013-4570 is classified as high due to its potential to cause a denial of service.
How do I fix CVE-2013-4570?
To fix CVE-2013-4570, upgrade MediaWiki to version 1.19.10, 1.21.4, or 1.22.1 or later.
Which versions of MediaWiki are affected by CVE-2013-4570?
CVE-2013-4570 affects MediaWiki versions prior to 1.19.10, 1.21.4, and 1.22.1.
What type of vulnerability is CVE-2013-4570?
CVE-2013-4570 is a denial of service vulnerability caused by a NULL pointer dereference.
Can CVE-2013-4570 be exploited remotely?
Yes, CVE-2013-4570 can be exploited remotely by attackers to crash the MediaWiki application.