Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2772

Опубликовано: 15 нояб. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 5

Описание

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

РелизСтатусПримечание
devel

released

1.4.1-1
hardy

DNE

lucid

released

1.2.4-1ubuntu0.4
maverick

released

1.2.5-2ubuntu0.3
natty

released

1.2.7-1ubuntu0.2
oneiric

released

1.4.0-1ubuntu0.1
upstream

needs-triage

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

debian
почти 15 лет назад

The get_dataroot_image_path function in lib/file.php in Mahara before ...

github
больше 4 лет назад

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

5 Medium

CVSS2