CVE-2014-1610
EPSS 48.0%
Description
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
How to fix CVE-2014-1610
To remediate CVE-2014-1610, upgrade the affected package to a fixed version below.
- Debian/mediawiki—upgrade to 1:1.19.11+dfsg-1 or later
Is CVE-2014-1610 being exploited?
Moderate — EPSS is 48.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1:1.19.11+dfsg-1