~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-4432

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2013-4432
2
 
PublicDate: 2014-05-19
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4432
5
 
 https://bazaar.launchpad.net/~mahara-release/mahara/1.7_STABLE/revision/5831
6
 
 http://www.openwall.com/lists/oss-security/2013/10/16/7
7
 
Description:
8
 
 Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not
9
 
 properly restrict access to folders, which allows remote authenticated
10
 
 users to read arbitrary folders (1) by leveraging an active folder tab
11
 
 loaded before permissions were removed or (2) via the folder parameter to
12
 
 artefact/file/groupfiles.php.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_mahara:
21
 
 upstream: https://bazaar.launchpad.net/~mahara-release/mahara/1.7_STABLE/revision/5831
22
 
upstream_mahara: released (1.7.3)
23
 
lucid_mahara: ignored (reached end-of-life)
24
 
precise_mahara: ignored (reached end-of-life)
25
 
precise/esm_mahara: DNE (precise was needed)
26
 
quantal_mahara: ignored (reached end-of-life)
27
 
raring_mahara: ignored (reached end-of-life)
28
 
saucy_mahara: ignored (reached end-of-life)
29
 
trusty_mahara: DNE
30
 
utopic_mahara: DNE
31
 
vivid_mahara: DNE
32
 
vivid/stable-phone-overlay_mahara: DNE
33
 
vivid/ubuntu-core_mahara: DNE
34
 
wily_mahara: DNE
35
 
xenial_mahara: DNE
36
 
yakkety_mahara: DNE
37
 
zesty_mahara: DNE
38
 
devel_mahara: DNE