CVE-2014-9487: XEE
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. NOTE: Related to CVE-2014-2053.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9487?
CVE-2014-9487 has been classified as a vulnerability that allows for potential exploitation including denial of service and unauthorized file access.
How do I fix CVE-2014-9487?
To mitigate CVE-2014-9487, update MediaWiki to versions 1.24.1, 1.23.8, 1.22.15, or 1.19.23 or later.
What kind of attack does CVE-2014-9487 facilitate?
CVE-2014-9487 facilitates XML External Entity (XXE) attacks that can lead to reading arbitrary files.
Which versions of MediaWiki are affected by CVE-2014-9487?
CVE-2014-9487 affects all MediaWiki versions prior to 1.24.1, as well as earlier 1.23, 1.22, and 1.19 versions.
Can CVE-2014-9487 lead to data leakage?
Yes, CVE-2014-9487 can lead to data leakage by allowing remote attackers to read arbitrary files on the server.