UBUNTU-CVE-2024-33103

Source
https://ubuntu.com/security/CVE-2024-33103
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-33103
Withdrawn
2025-06-23T15:58:13Z
Published
2024-04-30T18:15:00Z
Modified
2024-04-30T18:15:00Z
Summary
[none]
Details

** DISPUTED ** An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitability can only occur with a misconfiguration of the product.

References

Affected packages

Ubuntu:Pro:16.04:LTS / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/ubuntu/dokuwiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20140929.d-1
0.0.20140929.d-1ubuntu1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"

Ubuntu:Pro:18.04:LTS / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/ubuntu/dokuwiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20160626.a-2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"

Ubuntu:20.04:LTS / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/ubuntu/dokuwiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20180422.a-2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"

Ubuntu:22.04:LTS / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/ubuntu/dokuwiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20180422.a-2.1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"

Ubuntu:24.04:LTS / dokuwiki

Package

Name
dokuwiki
Purl
pkg:deb/ubuntu/dokuwiki

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.20220731.a-2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-33103.json"