Vulnerability Description
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | <= 1.15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.htmlPatchVendor Advisory
- http://secunia.com/advisories/39022Vendor Advisory
- http://secunia.com/advisories/39656
- http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES
- http://www.debian.org/security/2010/dsa-2022
- http://www.vupen.com/english/advisories/2010/0685Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1001
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.htmlPatchVendor Advisory
- http://secunia.com/advisories/39022Vendor Advisory
- http://secunia.com/advisories/39656
- http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES
- http://www.debian.org/security/2010/dsa-2022
- http://www.vupen.com/english/advisories/2010/0685Vendor Advisory
FAQ
What is CVE-2010-1190?
CVE-2010-1190 is a vulnerability with a CVSS score of 4.3 (MEDIUM). thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers t...
How severe is CVE-2010-1190?
CVE-2010-1190 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1190?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.