MediaWiki CPU And Memory Consumption Vulnerabilities
22 Sep. 2015
Summary
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an (1) SVG file or (2) XMP metadata in a PDF file, aka a "billion laughs attack,"
Credit:
The information has been provided by iSEC Partners, Bawolff, Jackmcbarn and the vendor.
An attacker can exploit these issues to perform unauthorized actions, bypass security restrictions, cause denial-of-service conditions, execute attacker-supplied HTML or JavaScript code in the context of the affected site, to steal cookie-based authentication credentials, upload arbitrary files, execute arbitrary code, or gain elevated privileges. This may aid in further attacks.