~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
Candidate: CVE-2011-4303
PublicDate: 2012-07-11
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4303
Description:
 lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does
 not set the correct registration_hubs.secret value during installation,
 which allows remote attackers to bypass intended access restrictions by
 leveraging the hubs feature.
Ubuntu-Description:
Notes:
 jdstrand> moodle 2.0 only
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_moodle:
upstream_moodle: needs-triage
hardy_moodle: ignored (reached end-of-life)
lucid_moodle: not-affected
maverick_moodle: not-affected
natty_moodle: not-affected
oneiric_moodle: not-affected
devel_moodle: not-affected (1.9.9.dfsg2-4)