1
Candidate: CVE-2012-3389
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3389
5
http://openwall.com/lists/oss-security/2012/07/17/1
6
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31692
8
Multiple cross-site scripting (XSS) vulnerabilities in
9
mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before
10
2.3.1 allow remote attackers to inject arbitrary web script or HTML via the
11
(1) lti_typename or (2) lti_toolurl parameter.
14
sbeattie> debian will in fix 2.2.3.dfsg-2.2
16
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=682203
22
upstream_moodle: needs-triage
23
hardy_moodle: ignored (reached end-of-life)
24
lucid_moodle: ignored (reached end-of-life)
25
natty_moodle: ignored (reached end-of-life)
26
oneiric_moodle: ignored (reached end-of-life)
27
precise_moodle: ignored (reached end-of-life)
28
precise/esm_moodle: DNE (precise was needs-triage)
29
quantal_moodle: ignored (reached end-of-life)
30
raring_moodle: ignored (reached end-of-life)
31
saucy_moodle: ignored (reached end-of-life)
33
utopic_moodle: ignored (reached end-of-life)
34
vivid_moodle: ignored (reached end-of-life)
35
vivid/stable-phone-overlay_moodle: DNE
36
vivid/ubuntu-core_moodle: DNE
37
wily_moodle: ignored (reached end-of-life)
39
yakkety_moodle: ignored (reached end-of-life)
40
zesty_moodle: ignored (reached end-of-life)