DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
BID:20257
Info
DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
| Bugtraq ID: | 20257 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2006 12:00AM |
| Updated: | Feb 20 2007 09:26PM |
| Credit: | Thomas Kindler reported the denial-of-service issue to the vendor. The vendor disclosed the command-execution issue. |
| Vulnerable: |
Gentoo Linux DocuWiki DocuWiki 2006-03-09 |
| Not Vulnerable: |
DocuWiki DocuWiki 2006-03-09e |
Discussion
DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
DokuWiki is prone to these vulnerabilities:
- A denial-of-service issue
- An arbitrary-command-execution issue
These issues present themselves when DocuWiki is configured to use ImageMagick.
The denial-of-service issue allows remote attackers to consume excessive CPU resources, denying service to legitimate users. The command-execution issue allows remote attackers to execute arbitrary shell commands with the privileges of the hosting webserver, facilitating a remote compromise of affected computers.
DokuWiki version 2006-03-09 is vulnerable to these issues; other versions may also be affected.
DokuWiki is prone to these vulnerabilities:
- A denial-of-service issue
- An arbitrary-command-execution issue
These issues present themselves when DocuWiki is configured to use ImageMagick.
The denial-of-service issue allows remote attackers to consume excessive CPU resources, denying service to legitimate users. The command-execution issue allows remote attackers to execute arbitrary shell commands with the privileges of the hosting webserver, facilitating a remote compromise of affected computers.
DokuWiki version 2006-03-09 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
Solution:
The vendor has released version 2006-03-09e to address these issues.
Please see the references for more information.
Solution:
The vendor has released version 2006-03-09e to address these issues.
Please see the references for more information.
References
DokuWiki With ImageMagick Remote Command Execution and Denial of Service Vulnerabilities
References:
References:
- [dokuwiki] [SECURITY ALERT] problems in fetch.php (DocuWiki)
- DocuWiki Home Page (DocuWiki)
- FS#924 �?? Image resize DOS-Attack in fetch.php (DokuWiki)
- FS#926 �?? Codeinjection in fetch.php (DokuWiki)