~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2015-0218

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2015-0218
2
 
PublicDate: 2015-06-01
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0218
5
 
 https://moodle.org/mod/forum/discuss.php?d=278618#p1196684
6
 
 http://www.openwall.com/lists/oss-security/2015/01/19/1
7
 
Description:
8
 
 Cross-site request forgery (CSRF) vulnerability in
9
 
 auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7,
10
 
 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to
11
 
 hijack the authentication of arbitrary users for requests that trigger a
12
 
 logout.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775842
17
 
Priority: medium
18
 
Discovered-by: Petr Skoda
19
 
Assigned-to:
20
 
 
21
 
Patches_moodle:
22
 
upstream_moodle: released (2.8.2, 2.7.4, 2.6.7)
23
 
lucid_moodle: ignored (reached end-of-life)
24
 
precise_moodle: ignored (reached end-of-life)
25
 
precise/esm_moodle: DNE (precise was needed)
26
 
trusty_moodle: needed
27
 
utopic_moodle: ignored (reached end-of-life)
28
 
vivid_moodle: ignored (reached end-of-life)
29
 
vivid/stable-phone-overlay_moodle: DNE
30
 
vivid/ubuntu-core_moodle: DNE
31
 
wily_moodle: ignored (reached end-of-life)
32
 
xenial_moodle: needed
33
 
yakkety_moodle: ignored (reached end-of-life)
34
 
zesty_moodle: ignored (reached end-of-life)
35
 
artful_moodle: needed
36
 
bionic_moodle: needed
37
 
devel_moodle: needed