VWE-2010-0103 Printable Version
This page is a chapter in Info Known Vulnerabilities
This page has been seen 4,485 times.
-
-
Created by on
-
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2010-0103 Related Report None Severity MEDIUM Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description Denial of Service amplification. The template parser attempts to resolve templates nested to an infinite depth.
Discovered July 27, 2010 Resolved July 28, 2010 Patches Available 3.0.2 Workaround Using the Wiki Code Manager, disable all BB-Codes that are used to create wiki links.
Even though this issue also affected the 2.x series, it was not addressed until a later patch, due to filename changes and a misconception that nested templates were only recently added in the 3.x series.