Candidate: CVE-2013-1817 PublicDate: 2019-11-20 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1817 http://www.openwall.com/lists/oss-security/2013/03/05/4 https://bugzilla.wikimedia.org/show_bug.cgi?id=43518 Description: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702305 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_mediawiki: upstream_mediawiki: released (1:1.19.4-1, 1.20.3, 1.19.4) hardy_mediawiki: ignored (reached end-of-life) lucid_mediawiki: ignored (reached end-of-life) oneiric_mediawiki: ignored (reached end-of-life) precise_mediawiki: ignored (reached end-of-life) precise/esm_mediawiki: DNE (precise was needed) quantal_mediawiki: ignored (reached end-of-life) raring_mediawiki: not-affected (1:1.19.4-1) saucy_mediawiki: not-affected (1:1.19.4-1) trusty_mediawiki: not-affected (1:1.19.4-1) trusty/esm_mediawiki: DNE utopic_mediawiki: not-affected (1:1.19.4-1) vivid_mediawiki: not-affected (1:1.19.4-1) vivid/stable-phone-overlay_mediawiki: DNE vivid/ubuntu-core_mediawiki: DNE wily_mediawiki: not-affected (1:1.19.4-1) xenial_mediawiki: DNE yakkety_mediawiki: not-affected (1:1.19.4-1) zesty_mediawiki: not-affected (1:1.19.4-1) artful_mediawiki: not-affected (1:1.19.4-1) bionic_mediawiki: not-affected (1:1.19.4-1) cosmic_mediawiki: not-affected (1:1.19.4-1) disco_mediawiki: not-affected (1:1.19.4-1) eoan_mediawiki: not-affected (1:1.19.4-1) focal_mediawiki: not-affected (1:1.19.4-1) groovy_mediawiki: not-affected (1:1.19.4-1) hirsute_mediawiki: not-affected (1:1.19.4-1) impish_mediawiki: not-affected (1:1.19.4-1) jammy_mediawiki: not-affected (1:1.19.4-1) devel_mediawiki: not-affected (1:1.19.4-1)