CVE-2015-2936: High severity mediawiki vulnerability
Published Apr 13, 2015
·Updated
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
Affected Software
2 affected components
MediaWiki MediaWiki=1.24.0
MediaWiki MediaWiki=1.24.1
Remediation
Event History
Apr 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2936?
CVE-2015-2936 is classified as a medium severity vulnerability due to its potential to cause denial of service by consuming CPU resources.
2
How do I fix CVE-2015-2936?
To address CVE-2015-2936, it is recommended to upgrade MediaWiki to version 1.24.2 or later.
3
Which versions of MediaWiki are affected by CVE-2015-2936?
CVE-2015-2936 affects MediaWiki versions 1.24.0 and 1.24.1.
4
What type of attack does CVE-2015-2936 enable?
CVE-2015-2936 enables remote attackers to execute a denial of service attack through the use of long passwords.
5
Is CVE-2015-2936 a local or remote vulnerability?
CVE-2015-2936 is a remote vulnerability, allowing attackers to exploit it over the network.