Описание
The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1.4.1-1 |
| hardy | DNE | |
| lucid | released | 1.2.4-1ubuntu0.4 |
| maverick | released | 1.2.5-2ubuntu0.3 |
| natty | released | 1.2.7-1ubuntu0.2 |
| oneiric | released | 1.4.0-1ubuntu0.1 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
5 Medium
CVSS2
Связанные уязвимости
The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.
The get_dataroot_image_path function in lib/file.php in Mahara before ...
The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.
5 Medium
CVSS2