First published: Mon Nov 09 2015(Updated: )
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <=1.23.10 | |
Wikimedia MediaWiki | =1.24.0 | |
Wikimedia MediaWiki | =1.24.1 | |
Wikimedia MediaWiki | =1.24.2 | |
Wikimedia MediaWiki | =1.24.3 | |
Wikimedia MediaWiki | =1.25.0 | |
Wikimedia MediaWiki | =1.25.1 | |
Wikimedia MediaWiki | =1.25.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8005 is classified as a moderate severity vulnerability due to its potential for exposing sensitive installation path information.
To fix CVE-2015-8005, upgrade MediaWiki to version 1.23.11, 1.24.4, or 1.25.3 or later.
CVE-2015-8005 affects MediaWiki versions before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3.
CVE-2015-8005 allows remote attackers to read the metadata of PNG thumbnail files, potentially leaking installation paths.
MediaWiki versions 1.23.10 and earlier, 1.24.0 to 1.24.3, and 1.25.0 to 1.25.2 are affected by CVE-2015-8005.