MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mediawiki | Mediawiki | 1.17 (including) | 1.17 (including) |
| Mediawiki | Mediawiki | 1.17-beta_1 (including) | 1.17-beta_1 (including) |
| Mediawiki | Mediawiki | 1.17.0 (including) | 1.17.0 (including) |
| Mediawiki | Mediawiki | 1.17.0-rc1 (including) | 1.17.0-rc1 (including) |
| Mediawiki | Mediawiki | 1.17.1 (including) | 1.17.1 (including) |
| Mediawiki | Mediawiki | 1.17.2 (including) | 1.17.2 (including) |
| Mediawiki | Ubuntu | hardy | * |
| Mediawiki | Ubuntu | lucid | * |
| Mediawiki | Ubuntu | maverick | * |
| Mediawiki | Ubuntu | natty | * |
| Mediawiki | Ubuntu | oneiric | * |
| Mediawiki | Ubuntu | precise | * |