Candidate: CVE-2013-2114 PublicDate: 2013-11-18 02:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2114 https://www.openwall.com/lists/oss-security/2013/05/24/3 Description: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mediawiki: upstream: http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.7.patch.gz upstream_mediawiki: released (1:1.19.7+dfsg-1) lucid_mediawiki: ignored (reached end-of-life) precise_mediawiki: ignored (reached end-of-life) precise/esm_mediawiki: DNE (precise was needed) quantal_mediawiki: ignored (reached end-of-life) raring_mediawiki: ignored (reached end-of-life) saucy_mediawiki: not-affected (1:1.19.7+dfsg-1) trusty_mediawiki: not-affected (1:1.19.7+dfsg-1) trusty/esm_mediawiki: DNE utopic_mediawiki: not-affected (1:1.19.7+dfsg-1) vivid_mediawiki: not-affected (1:1.19.7+dfsg-1) vivid/stable-phone-overlay_mediawiki: DNE vivid/ubuntu-core_mediawiki: DNE wily_mediawiki: not-affected (1:1.19.7+dfsg-1) xenial_mediawiki: DNE yakkety_mediawiki: not-affected (1:1.19.7+dfsg-1) zesty_mediawiki: not-affected (1:1.19.7+dfsg-1) artful_mediawiki: not-affected (1:1.19.7+dfsg-1) bionic_mediawiki: not-affected (1:1.19.7+dfsg-1) cosmic_mediawiki: not-affected (1:1.19.7+dfsg-1) disco_mediawiki: not-affected (1:1.19.7+dfsg-1) eoan_mediawiki: not-affected (1:1.19.7+dfsg-1) focal_mediawiki: not-affected (1:1.19.7+dfsg-1) groovy_mediawiki: not-affected (1:1.19.7+dfsg-1) hirsute_mediawiki: not-affected (1:1.19.7+dfsg-1) impish_mediawiki: not-affected (1:1.19.7+dfsg-1) jammy_mediawiki: not-affected (1:1.19.7+dfsg-1) devel_mediawiki: not-affected (1:1.19.7+dfsg-1)