MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions by using an IP address that was not supposed to have been allowed.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T97897 | third party advisory patch |
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.html | mailing list release notes patch vendor advisory |
http://www.openwall.com/lists/oss-security/2015/12/23/7 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2015/12/21/8 | mailing list third party advisory patch |