CVE-2015-8005
Publication date 9 November 2015
Last updated 24 July 2024
Ubuntu priority
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
Status
Package | Ubuntu Release | Status |
---|---|---|
mediawiki | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
sbeattie
mediawiki package have a known default install location on debian/ubuntu, so not likely exposing info that isn’t already known