The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | 1.17 (including) | 1.17 (including) |
Mediawiki | Mediawiki | 1.17-beta_1 (including) | 1.17-beta_1 (including) |
Mediawiki | Mediawiki | 1.17.0 (including) | 1.17.0 (including) |
Mediawiki | Mediawiki | 1.17.0-rc1 (including) | 1.17.0-rc1 (including) |
Mediawiki | Mediawiki | 1.17.1 (including) | 1.17.1 (including) |
Mediawiki | Mediawiki | 1.17.2 (including) | 1.17.2 (including) |
Mediawiki | Ubuntu | hardy | * |
Mediawiki | Ubuntu | lucid | * |
Mediawiki | Ubuntu | natty | * |
Mediawiki | Ubuntu | oneiric | * |
Mediawiki | Ubuntu | precise | * |