CVE-2015-2942: High severity mediawiki vulnerability
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an (1) SVG file or (2) XMP metadata in a PDF file, aka a "billion laughs attack," a different vulnerability than CVE-2015-2937.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2942?
CVE-2015-2942 is categorized as a denial of service vulnerability due to potential high CPU and memory consumption.
How do I fix CVE-2015-2942?
To fix CVE-2015-2942, upgrade MediaWiki to versions 1.19.24, 1.23.9, 1.24.2 or later.
Which versions of MediaWiki are affected by CVE-2015-2942?
CVE-2015-2942 affects MediaWiki versions earlier than 1.19.24, 1.23.9, and 1.24.2 when using HHVM.
What is the nature of the attack described in CVE-2015-2942?
The attack involves a large number of nested entity references in SVG files or XMP metadata in PDF files, leading to denial of service.
Can CVE-2015-2942 be exploited remotely?
Yes, CVE-2015-2942 can be exploited remotely without authentication.