1
Candidate: CVE-2012-3387
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3387
5
http://openwall.com/lists/oss-security/2012/07/17/1
6
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33948
8
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether
9
references are permitted in a file upload, which allows remote
10
authenticated users to bypass intended alias (aka shortcut) restrictions
11
via a client that omits this check.
14
sbeattie> moodle 2.3.x only?
21
upstream_moodle: needs-triage
22
hardy_moodle: ignored (reached end-of-life)
23
lucid_moodle: ignored (reached end-of-life)
24
natty_moodle: ignored (reached end-of-life)
25
oneiric_moodle: ignored (reached end-of-life)
26
precise_moodle: ignored (reached end-of-life)
27
precise/esm_moodle: DNE (precise was needs-triage)
28
quantal_moodle: ignored (reached end-of-life)
29
raring_moodle: ignored (reached end-of-life)
30
saucy_moodle: ignored (reached end-of-life)
31
trusty_moodle: needs-triage
32
utopic_moodle: ignored (reached end-of-life)
33
vivid_moodle: ignored (reached end-of-life)
34
vivid/stable-phone-overlay_moodle: DNE
35
vivid/ubuntu-core_moodle: DNE
36
wily_moodle: ignored (reached end-of-life)
37
xenial_moodle: needs-triage
38
yakkety_moodle: ignored (reached end-of-life)
39
zesty_moodle: ignored (reached end-of-life)
40
artful_moodle: needs-triage
41
bionic_moodle: needs-triage
42
devel_moodle: needs-triage