Oval Definition:oval:com.ubuntu.precise:def:20141610000
Revision Date:2014-01-30Version:1
Title:CVE-2014-1610 on Ubuntu 12.04 LTS (precise) - medium.
Description:MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-1610
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'mediawiki' package in precise is affected and needs fixing.
  • BACK