5
CVSSv2

CVE-2013-4570

Published: 12/05/2014 Updated: 12/05/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki prior to 1.19.10, 1.2x prior to 1.21.4, and 1.22.x prior to 1.22.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via vectors related to converting Lua data structures to PHP, as demonstrated by passing { [{}] = 1 } to a module function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mediawiki mediawiki 1.22.0

mediawiki mediawiki 1.19

mediawiki mediawiki 1.19.4

mediawiki mediawiki 1.19.5

mediawiki mediawiki 1.19.6

mediawiki mediawiki 1.19.7

mediawiki mediawiki 1.19.0

mediawiki mediawiki 1.19.2

mediawiki mediawiki

mediawiki mediawiki 1.19.1

mediawiki mediawiki 1.19.3

mediawiki mediawiki 1.19.8

mediawiki mediawiki 1.21.1

mediawiki mediawiki 1.21

mediawiki mediawiki 1.21.2

mediawiki mediawiki 1.21.3