CVE-2015-8005: Infoleak
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8005?
CVE-2015-8005 is classified as a moderate severity vulnerability due to its potential for exposing sensitive installation path information.
How do I fix CVE-2015-8005?
To fix CVE-2015-8005, upgrade MediaWiki to version 1.23.11, 1.24.4, or 1.25.3 or later.
Who is affected by CVE-2015-8005?
CVE-2015-8005 affects MediaWiki versions before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3.
What type of attack does CVE-2015-8005 allow?
CVE-2015-8005 allows remote attackers to read the metadata of PNG thumbnail files, potentially leaking installation paths.
What versions of MediaWiki contain the vulnerability described in CVE-2015-8005?
MediaWiki versions 1.23.10 and earlier, 1.24.0 to 1.24.3, and 1.25.0 to 1.25.2 are affected by CVE-2015-8005.