First published: Mon Apr 13 2015(Updated: )
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | =1.24.0 | |
Wikimedia MediaWiki | =1.24.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2936 is classified as a medium severity vulnerability due to its potential to cause denial of service by consuming CPU resources.
To address CVE-2015-2936, it is recommended to upgrade MediaWiki to version 1.24.2 or later.
CVE-2015-2936 affects MediaWiki versions 1.24.0 and 1.24.1.
CVE-2015-2936 enables remote attackers to execute a denial of service attack through the use of long passwords.
CVE-2015-2936 is a remote vulnerability, allowing attackers to exploit it over the network.