The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containing <cross-domain-policy> in a PHP format request, which causes the string length to change when converting the request to <NOT-cross-domain-policy>.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
http://securitytracker.com/id?1031301 | vdb entry |
https://phabricator.wikimedia.org/T73478 | exploit |
http://www.openwall.com/lists/oss-security/2014/12/03/9 | mailing list |
http://www.openwall.com/lists/oss-security/2014/12/04/16 | mailing list |
http://www.debian.org/security/2014/dsa-3100 | vendor advisory |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html | mailing list patch vendor advisory |