~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2015-3175

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2015-3175
2
 
PublicDate: 2015-06-01
3
 
References: 
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3175
5
 
 http://www.openwall.com/lists/oss-security/2015/05/18/1
6
 
 https://moodle.org/mod/forum/discuss.php?d=313682
7
 
Description:
8
 
 Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x
9
 
 before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote
10
 
 attackers to redirect users to arbitrary web sites and conduct phishing
11
 
 attacks via vectors involving an error page that links to a URL from an
12
 
 HTTP Referer header.
13
 
Ubuntu-Description: 
14
 
Notes: 
15
 
Bugs: 
16
 
Priority: medium
17
 
Discovered-by: Dingjie Yang
18
 
Assigned-to: 
19
 
 
20
 
Patches_moodle:
21
 
 upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-49179
22
 
upstream_moodle: released (2.9, 2.8.6, 2.7.8 and 2.6.11)
23
 
precise_moodle: ignored (reached end-of-life)
24
 
precise/esm_moodle: DNE (precise was needs-triage)
25
 
trusty_moodle: needs-triage
26
 
utopic_moodle: ignored (reached end-of-life)
27
 
vivid_moodle: ignored (reached end-of-life)
28
 
vivid/stable-phone-overlay_moodle: DNE
29
 
vivid/ubuntu-core_moodle: DNE
30
 
wily_moodle: ignored (reached end-of-life)
31
 
xenial_moodle: needed
32
 
yakkety_moodle: ignored (reached end-of-life)
33
 
zesty_moodle: ignored (reached end-of-life)
34
 
artful_moodle: needed
35
 
bionic_moodle: needed
36
 
devel_moodle: needed